Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumContained
WELLESLEY ASSET MANAGEMENT, INC.
bd_619dbe14822b2bcc · schema v1 · pii pii-v1
Full breach record for WELLESLEY ASSET MANAGEMENT, INC. →Wellesley Asset Management, Inc. reported a data security incident on September 26, 2024, affecting 67 New Hampshire residents. On May 20, 2024, the firm discovered an employee's email account was compromised. The attacker could have viewed emails and attachments containing client names, SSNs, and financial account numbers. No data was downloaded. WAM engaged forensic experts, notified law enforcement, and offered two years of credit monitoring via Experian.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_9b0411a87e5f067fMontana State AGfiled 2024-09-26Candidate
- bd_9d79b3638519b194Maine State AGfiled 2024-09-27(1d gap)Verified
- bd_42fb4b336a8dd458Indiana State AGfiled 2024-09-20(6d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/wellesley-asset-management-20240926.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2024
- Raw hash
- 724d5194a753b88c56fc7c1f039fe6f54c650d2b59a84bb66b75b5f74670e5b5
Reporting entity
- Name
- WELLESLEY ASSET MANAGEMENT, INC.norm: wellesley asset management
- Domain
- wam.com
Victim entity
- Name
- WELLESLEY ASSET MANAGEMENT, INC.norm: wellesley asset management
- Domain
- wam.com
Incident
- Discovered
- May 20, 2024
- Materiality determined
- —
- Notification sent
- Sep 20, 2024
- Affected individuals
- 67
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement authorities
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 weeks(129 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.