Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTPCIMediumContained
Grandizio Wilkins Little & Matthews, LLP
bd_68e41a6065c14fc1 · schema v1 · pii pii-v1
Full breach record for Grandizio Wilkins Little & Matthews, LLP →Grandizio Wilkins Little & Matthews, LLP (GWLM), an accounting firm, notified the New Hampshire Attorney General of a data security incident affecting approximately 22 NH residents. On June 7, 2021, GWLM discovered unauthorized access to an employee's email account, likely via phishing. The incident potentially exposed names, SSNs, medical info, driver's license info, financial account info, and payment card data. GWLM engaged forensic experts, reported to the FBI, and sent notification letters on January 14, 2022, offering 12 months of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_35b3a7fba97c5d33Delaware State AGfiled 2022-01-14Candidate
- bd_628b4a53f2a6ffd7Maine State AGfiled 2022-01-14Verified by operator
- bd_2912bfae25457784Delaware State AGfiled 2021-12-17(28d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/grandizio-wilkins-little-matthews-20220114.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2022
- Raw hash
- f610b0e960269e0f3f4303368e4565c1c6719ba39c661dcdaaf88588f34ec797
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Grandizio Wilkins Little & Matthews, LLPnorm: grandizio wilkins little matthews
Incident
- Discovered
- Jun 7, 2021
- Materiality determined
- —
- Notification sent
- Jan 14, 2022
- Affected individuals
- 22
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTPCI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Reported the incident to the Federal Bureau of Investigation (FBI)
- Initial access
- phishing_link
Compliance
- Time to disclose
- 32 weeks(221 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.