Social EngineeringPhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedPIIIDENTITY_BASICFINANCIALLowContained
BRUNSWICK CORPORATION
bd_886ffd86dbb50291 · schema v1 · pii pii-v1
Full breach record for BRUNSWICK CORPORATION →Brunswick Corporation reported a phishing incident affecting a MarineMax employee. An attacker clicked a phishing link on March 27, 2024, hijacked the account, and accessed email files. The breach was detected on April 10, 2024. One New Hampshire resident's W9 data (business phone, email) was exposed. Remediation included password resets and credit monitoring offers.
Leak gap clock⏱ Leak >90d7 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
A leak claim by toufan about this victim predates this filing by 164 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/marinemax-searay-20240531.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2024
- Raw hash
- f08f9aa0345c2070a722dda1dc74b3824d2ee0009035a2067f47d268e70d5b6d
Reporting entity
- Name
- BRUNSWICK CORPORATIONnorm: brunswick
- Domain
- brunswick.com
Victim entity
- Name
- BRUNSWICK CORPORATIONnorm: brunswick
- Domain
- brunswick.com
Incident
- Discovered
- Apr 10, 2024
- Materiality determined
- May 14, 2024
- Notification sent
- May 28, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed an 8-K filing breach notification with the US Securities and Exchange Commission (SEC)
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.