DisclosureLens
Social EngineeringTelecom & MediaInformationPhishingStolen CredentialsEmployee Data InvolvedMulti-Stage ChainIdentity (basic)Government IDFinancial accountEmploymentMediumContained

Gannett Company, Inc.

bd_7f12b327f14904e7 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 30, 2017

Filed

Apr 28, 2017

To disclose

29 days

Affected

Not disclosed

Linked

4 filings

Confidence

64%
Full breach record for Gannett Company, Inc.3 incidents on file

Gannett Company, Inc. disclosed a phishing attack targeting HR department employees, compromising Office 365 credentials. The attacker sent further phishing emails and attempted a fraudulent wire transfer, which was unsuccessful. Potential exposure included employee PII, SSNs, bank account numbers, and salary information. No sensitive data acquisition was confirmed, but notice was sent out of caution. Accounts were locked, credentials reset, and forensic investigation confirmed no other systems were impacted.

California clockDiscovered Mar 30, 2017Notified Apr 28, 201729d CA 60-day OK29 days discovery → filing

Incident timeline

undetected · 2 days
discovery → filing · 29 days

Mar 28, 2017

Begins

Mar 30, 2017

Discovered

Apr 28, 2017

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Montana State AGApr 28 · first
Massachusetts State AGApr 28 · first
New Hampshire State AGApr 28 · first
California State AGApr 28 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.