The PenFacs Group
bd_5ddabd7c0c6e114d · schema v1 · pii pii-v1
Full breach record for The PenFacs Group →The PenFacs Group notified the NH Attorney General of a phishing incident affecting 12 NH residents. Unauthorized access occurred around Nov 15, 2021, discovered Feb 23, 2022. Data exposed included SSNs, driver's licenses, financial accounts, and PHI. PenFacs engaged forensic experts, notified law enforcement, and provided 1 year of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 15, 2021
Begins
Feb 23, 2022
Discovered
Sep 30, 2022
Filed
vs. sector median
+23 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_852399ec6505e9eb2022-09-30Verified
- Montana State AGbd_708454173ae85d212022-11-03 · +34dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 30 (MA), last Nov 3 (MT) — a 34-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.