Social EngineeringPhishingBECData ExfiltratedRansom DemandedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIALMediumContained
Dennis Group
bd_565272e3ff0b63e7 · schema v1 · pii pii-v1
Full breach record for Dennis Group →The Dennis Group, Inc. notified the New Hampshire Attorney General of a Business Email Compromise (BEC) incident occurring on August 5, 2016. Attackers spoofed the CEO's email to fraudulently request W-2 forms containing names, addresses, SSNs, and compensation data for 3 New Hampshire residents. The company discovered the fraud the same night, notified the FBI, and provided credit monitoring services to affected employees.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/dennis-group-20160812.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2016
- Raw hash
- 6d95c4efe8492e5ace31df5160e84e708718e8a17865dc8df79371f25cd15c93
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Dennis Groupnorm: dennis group
- Domain
- dennisgroup.com
Incident
- Discovered
- Aug 5, 2016
- Materiality determined
- —
- Notification sent
- Aug 12, 2016
- Affected individuals
- 3
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Providing written notice of this incident to other state regulators as necessary
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.