Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIEMPLOYMENTLowContained
Smead Manufacturing
bd_794a55402f64bc47 · schema v1 · pii pii-v1
Full breach record for Smead Manufacturing →Smead Manufacturing notified the NH AG of unauthorized access to an employee email account between Feb 1-7, 2023. The breach likely resulted from phishing, compromising credentials. Affected data included former and current employee information. One NH resident was identified. Smead secured the account, investigated, and offered 2 years of credit monitoring via Experian.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b20393e31e8a10f5Montana State AGfiled 2023-03-29(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/smead-manufacturing-20230403.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2023
- Raw hash
- 98cb069373f2cab0a6199d9503e8f7dc12f13719da8a176ea7565877481d163b
Reporting entity
- Name
- Smead Manufacturingnorm: smead manufacturing
Victim entity
- Name
- Smead Manufacturingnorm: smead manufacturing
Incident
- Discovered
- Feb 1, 2023
- Materiality determined
- Feb 24, 2023
- Notification sent
- Mar 29, 2023
- Affected individuals
- 1
- Data types
- PIIEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.