HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Phillips Exeter Academy
bd_66011e77b92c8789 · schema v1 · pii pii-v1
Full breach record for Phillips Exeter Academy →Phillips Academy notified the New Hampshire Attorney General of a data security incident in May 2021. Unauthorized parties accessed employee email accounts between May 8 and May 25, 2021. The incident potentially exposed New Hampshire residents' names, Social Security numbers, driver's license numbers, and financial account information. Phillips Academy notified 99 NH residents and offered credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_21b2007a6968edbfMontana State AGfiled 2021-09-21Candidate
- bd_a7759522c19f7928Maine State AGfiled 2021-09-21Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/phillips-academy-20210921.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 21, 2021
- Raw hash
- f40405c1996ef597ca9214e5cd7a6451a8c9ec9b0fe1b2e7b7003a2f1fd564e6
Reporting entity
- Name
- Phillips Exeter Academynorm: phillips exeter academy
Victim entity
- Name
- Phillips Exeter Academynorm: phillips exeter academy
Incident
- Discovered
- May 1, 2021
- Materiality determined
- —
- Notification sent
- Sep 21, 2021
- Affected individuals
- 99
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 weeks(143 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.