Social EngineeringPhishingBECMulti-Stage ChainTargetedFINANCIAL_ACCOUNTLowContained
Catholic Charities New Hampshire
bd_8a7dbc14af7d486a · schema v1 · pii pii-v1
Full breach record for Catholic Charities New Hampshire →Catholic Charities New Hampshire (CCNH) reported a Business Email Compromise (BEC) incident. On April 11, 2025, an employee provided a vendor's ACH form to attackers who impersonated the vendor via phishing. CCNH detected the attack on April 16, 2025. No funds were diverted, but vendor banking data was exposed. CCNH is providing supplemental notices and enhancing staff training.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/catholic-charities-new-hampshire-20250523.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2025
- Raw hash
- 3280c9967a7c2dd77221497a0049dc9652f7bf0f5c4f38f4beae716f5067a746
Reporting entity
- Name
- Catholic Charities New Hampshirenorm: catholic charities new hampshire
- Domain
- cc-nh.org
Victim entity
- Name
- Catholic Charities New Hampshirenorm: catholic charities new hampshire
- Domain
- cc-nh.org
Incident
- Discovered
- Apr 16, 2025
- Materiality determined
- —
- Notification sent
- May 19, 2025
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.