DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingCustomer Data InvolvedIdentity (basic)Financial accountLowContained

Institute for Supply Management

bd_7dca1ca7672064e5 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Apr 3, 2018

To disclose

Affected

1state residents only

Confidence

66%
Full breach record for Institute for Supply Management

Institute for Supply Management (ISM) notified the NH Attorney General of a phishing incident occurring on January 25, 2018. Unauthorized senders sent phishing emails with links to a fake Docusign site to contacts in an ISM employee's mobile device. While no evidence of network access or data breach was found, one New Hampshire resident was notified out of caution due to potential exposure of email address, name, and credit/debit card number. ISM reset passwords and accelerated two-factor authentication rollout.

Incident timeline

Jan 25, 2018

Begins

Apr 3, 2018

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.