DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDEmploymentMediumContained

GreyHealth Group

bd_7acafbed1ef56764 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2018

Filed

Mar 1, 2018

To disclose

23 days

Affected

683

Confidence

67%
Full breach record for GreyHealth Group

GreyHealth Group notified the NH AG that an employee sent 2017 W2 forms (containing SSNs, names, addresses, salaries) to an unauthorized recipient on Jan 26, 2018, after being targeted by a phishing scam. The company discovered the incident on Feb 6, 2018. Approximately 683 US employees were affected, including 1 NH resident. The company offered 2 years of credit monitoring via Experian.

Incident timeline

undetected · 11 days
discovery → filing · 23 days

Jan 26, 2018

Begins

Feb 6, 2018

Discovered

Mar 1, 2018

Filed

vs. sector median

11 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed683 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.