Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Cumberland Advisors, LLC
bd_6ab5b3b9d1b51cd8 · schema v1 · pii pii-v1
Full breach record for Cumberland Advisors, LLC →Cumberland Advisors, Inc. reported a phishing incident where unauthorized access to two employee email accounts occurred between August 31 and September 5, 2023. The breach was discovered on September 5, 2023. The incident potentially exposed personal information of 30 New Hampshire residents. Cumberland engaged forensic specialists, notified law enforcement, and provided one year of credit monitoring via Experian to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_e75969bf74119acfMaine State AGfiled 2024-02-14Candidate
- bd_27f60e7defb708fcMontana State AGfiled 2023-12-20(56d gap)Candidate
- bd_59e92d07c3db90cfMaine State AGfiled 2023-12-20(56d gap)Verified
- bd_70f1d52df37b37f8Vermont State AGfiled 2023-12-20(56d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cumberland-advisors-20240214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2024
- Raw hash
- 69d8218a6bc6f79b6e993bcd1cc19375153e7955494a45ac3da293c70ff6bbc7
Reporting entity
- Name
- Cumberland Advisors, LLCnorm: cumberland advisors
Victim entity
- Name
- Cumberland Advisors, LLCnorm: cumberland advisors
Incident
- Discovered
- Sep 5, 2023
- Materiality determined
- Nov 20, 2023
- Notification sent
- Dec 20, 2023
- Affected individuals
- 30
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementProvided written notice to relevant state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.