Social EngineeringPhishingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Deloitte
bd_88bc0706d808c993 · schema v1 · pii pii-v1
Full breach record for Deloitte →Deloitte Services LP notified the New Hampshire Attorney General on April 2, 2026, of a social engineering incident affecting one NH resident. On February 13, 2026, an unauthorized actor impersonated an employee via phone to reset credentials and access the employee's personnel account, exposing the employee's name and Social Security number. Deloitte discovered the incident on February 18, 2026, reset credentials, and implemented process changes. The company offered one year of Experian IdentityWorks to the affected individual.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/deloitte-services-20260402.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2026
- Raw hash
- 748c2df1adbe48e5fdd912d0fe3095ae5132cab089b15f8289ee96fbbed508d7
Reporting entity
- Name
- Deloittenorm: deloitte
- Domain
- deloitte.com
Victim entity
- Name
- Deloittenorm: deloitte
- Domain
- deloitte.com
Incident
- Discovered
- Feb 18, 2026
- Materiality determined
- —
- Notification sent
- Apr 3, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.