MisusePrivilege AbuseEmployee Data InvolvedPIIIDENTITY_BASICLowContained
Sierra Club
bd_6210b1910769410b · schema v1 · pii pii-v1
Full breach record for Sierra Club →Sierra Club notified New Hampshire residents on October 4, 2023, regarding a data incident involving a former employee. On or about February 3, 2023, the employee forwarded or blind-copied a file containing personal information of other Sierra Club employees to a personal email account. The activity was discovered during a security audit. The employee is no longer with the organization. Two New Hampshire residents were notified. Credit monitoring services were provided via Experian.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0817cb1dfc1ba95fMaine State AGfiled 2023-10-05Candidate
- bd_2424595bc8ca2c33Vermont State AGfiled 2023-10-05Verified
- bd_dfe987f053485cfeMontana State AGfiled 2023-10-05Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sierra-club-20231005.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2023
- Raw hash
- edbf860ca2117ad28a9bbcdf32257f7b0775f042d111d687c2f9e8a07fd8e054
Reporting entity
- Name
- Sierra Clubnorm: sierra club
Victim entity
- Name
- Sierra Clubnorm: sierra club
Incident
- Discovered
- Feb 3, 2023
- Materiality determined
- —
- Notification sent
- Oct 4, 2023
- Affected individuals
- 2
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Provided written notice of this incident to relevant state regulators, as necessary
- Initial access
- insider_action
Compliance
- Time to disclose
- 35 weeks(244 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.