MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedRansom PaidSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Perkins & Co.
bd_5676fa52897cd2f0 · schema v1 · pii pii-v1
Full breach record for Perkins & Co. →Perkins & Co, a tax and accounting firm, notified the New Hampshire Attorney General of a ransomware attack on its third-party cloud hosting vendor, Netgain Technologies. The incident, occurring between November 8 and December 3, 2020, involved unauthorized access, data exfiltration, and file encryption. Netgain paid a ransom and returned data. 176 New Hampshire residents were affected, with personal information including names, SSNs, DOBs, and benefit account details potentially compromised. Perkins offered 12 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_bed885cbbe06ca85Maine State AGfiled 2021-05-04(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/perkins-20210503.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2021
- Raw hash
- 28f90eed8cb282a6ebb02f40480138e5c8bd231b840a6b56bfe9a209fca724e6
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Perkins & Co.norm: perkins
- Domain
- perkinsaccounting.com
Incident
- Discovered
- Dec 3, 2020
- Materiality determined
- —
- Notification sent
- Apr 23, 2021
- Affected individuals
- 176
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to applicable state data privacy regulatory authorities
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 weeks(151 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.