Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
GPD Holdings LLC
bd_695fa07a8efe326a · schema v1 · pii pii-v1
Full breach record for GPD Holdings LLC →GPD Holdings, LLC d/b/a CoinFlip reported a data breach affecting approximately 3,500 individuals. The incident involved the compromise of an employee's email account via a phishing attack, leading to the unauthorized access and exfiltration of customer data, including names, addresses, and payment card information. The company engaged forensic investigators and law enforcement, reset credentials, and notified affected consumers.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1138cf7024df8a8dOregon State AGfiled 2023-10-24Verified
- bd_aacc11b29e88ad4fMaine State AGfiled 2023-10-24Verified
- bd_17d3f46501cb18a4California State AGfiled 2023-10-23(1d gap)Verified
- bd_5ea2f46c0afee68fVermont State AGfiled 2023-10-20(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 4d gap
- bd_ecac09bfda9a1bd5Montana State AGfiled 2023-10-20(4d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gpd-holdings-dba-coinflip-20231024.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 24, 2023
- Raw hash
- cfe6763715ca4b85dce1419033436d99bb9a98a09308e7b1d8262ead15ee0312
Reporting entity
- Name
- GPD Holdings LLCnorm: gpd holdings
Victim entity
- Name
- GPD Holdings LLCnorm: gpd holdings
Incident
- Discovered
- Aug 7, 2023
- Materiality determined
- —
- Notification sent
- Oct 20, 2023
- Affected individuals
- 3,500
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed security breach notification with New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.