Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Congo, LLC
bd_5978719160b5d3a7 · schema v1 · pii pii-v1
Full breach record for Congo, LLC →Congo, LLC, a distribution company based in Louisville, KY, notified the New Hampshire Attorney General of a data security incident in April 2021. Unauthorized access to an employee email account occurred in March 2021, likely via a phishing compromise of an Office 365 account. The breach potentially exposed personal information of one New Hampshire resident, including names, SSNs, driver's license numbers, and bank account details. Congo engaged forensic investigators, notified the FBI, and provided 12 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/congo-20210526.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2021
- Raw hash
- 72050cc75954aba66938c6e7723100fc5d571e356bd4a4561eae418f89d9eaae
Reporting entity
- Name
- Congo, LLCnorm: congo
Victim entity
- Name
- Congo, LLCnorm: congo
Incident
- Discovered
- Apr 1, 2021
- Materiality determined
- —
- Notification sent
- May 28, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.