Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALMediumContained
Santa Rosa Consulting Inc.
bd_7cbdf4edc4d1de9d · schema v1 · pii pii-v1
Full breach record for Santa Rosa Consulting Inc. →Santa Rosa Consulting Inc. notified the New Hampshire Attorney General of a phishing attack on May 8, 2016, where an employee was spoofed into providing W-2 data (names, addresses, SSNs, wages) to a fraudster. One New Hampshire resident was affected. The company engaged Kroll for identity monitoring and Butzel Long for legal counsel. Notification to the employee was sent on May 27, 2016.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/santa-rosa-consulting-20160613.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2016
- Raw hash
- 55578db9b3bff0efedcec25ebd91c63412fe3ba3f98d7b334d8a42b61d3de54d
Reporting entity
- Name
- Santa Rosa Consulting Inc.norm: santa rosa consulting
Victim entity
- Name
- Santa Rosa Consulting Inc.norm: santa rosa consulting
Incident
- Discovered
- May 8, 2016
- Materiality determined
- —
- Notification sent
- May 27, 2016
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Joseph Foster
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.