Aladdin Capital
bd_8d1a73eabce68831 · schema v1 · pii pii-v1
Full breach record for Aladdin Capital →Aladdin Capital, a commercial equipment leasing firm, notified the NH AG of a cybersecurity incident discovered on Nov 24, 2020. Unauthorized access occurred to two employee email accounts between Nov 18-23, 2020, likely via phishing. Data exposed included names, SSNs, driver's licenses, DOBs, and financial info. 2,318 individuals notified; 1 NH resident. Remediation included forensic investigation, password resets, MFA implementation, and credit monitoring offers.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 18, 2020
Begins
Nov 24, 2020
Discovered
Sep 30, 2021
Filed
vs. sector median
+36 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_1f948f109b746e052021-09-27 · +3dCandidate
- Indiana State AGbd_370332305476fac32021-09-27 · +3dVerified
- Massachusetts State AGbd_793651122d4c78d72021-09-27 · +3dVerified
- Maine State AGbd_acdce82b2c9b79552021-09-27 · +3dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.