DisclosureLens
Social EngineeringConstructionConstructionPhishingEmployee Data InvolvedIdentity (basic)Government IDFinancial accountEmploymentMediumActive

Michels Corporation

bd_71e9246106b6a5fa · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 18, 2016

Filed

Apr 25, 2016

To disclose

7 days

Affected

48state residents only

Linked

4 filings

Confidence

66%
Full breach record for Michels Corporation

Michels Corporation notified the NH Attorney General of a phishing incident on April 16, 2016, where an employee was tricked into disclosing W-2 information for current and former employees. The data exposed included names, addresses, SSNs, and earnings/withholding info. 48 New Hampshire residents were affected. The company discovered the incident on April 18, 2016, and began mailing notices on April 27, 2016. Law enforcement was notified, and identity protection services were offered.

Incident timeline

undetected · 2 days
discovery → filing · 7 days

Apr 16, 2016

Begins

Apr 18, 2016

Discovered

Apr 25, 2016

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Massachusetts State AGApr 25 · first
New Hampshire State AGApr 25 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.