Social EngineeringPhishingTargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Hutchinson and Bloodgood LLP
bd_4d2d098d5a3c6a98 · schema v1 · pii pii-v1
Full breach record for Hutchinson and Bloodgood LLP →Hutchinson and Bloodgood LLP disclosed a data breach involving a targeted spear-phishing email sent to an employee on December 21, 2016. The incident potentially exposed clients' names, addresses, and Social Security numbers. The firm notified the FBI, IRS, and state taxing authorities and offered one year of identity protection services to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a09991b5b2be07fbMontana State AGfiled 2017-02-01(37d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66868
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 10, 2017
- Raw hash
- 10f7b86fc908c305790782d261f5adcf4bbff0c0a3b166bb8859a6bad6581be3
Reporting entity
- Name
- Hutchinson and Bloodgood LLPnorm: hutchinson and bloodgood
Victim entity
- Name
- Hutchinson and Bloodgood LLPnorm: hutchinson and bloodgood
Incident
- Discovered
- Dec 21, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified the FBINotified the IRS FTBNotified related state taxing authorities
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.