McNair & Company
bd_8d704966dac7a1a0 · schema v1 · pii pii-v1
Full breach record for McNair & Company →McNair & Company notified the New Hampshire Attorney General of a cybersecurity incident involving unauthorized access to an employee's email account. The breach occurred between April 27, 2021, and May 12, 2021. The investigation determined that names, Social Security numbers, driver's license numbers, passport numbers, tax identification numbers, limited health information, and financial account numbers of 1 New Hampshire resident may have been accessed. McNair engaged a cybersecurity firm, secured the email environment, mailed notification letters, and offered one year of credit monitoring through Kroll.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mcnair-20210827.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2021
- Raw hash
- c769bd2835b66bd61e3a008f55545d4fe9a1c20908cdd8645d8a5ef657d35404
Reporting entity
- Name
- McNair & Companynorm: mcnair
- Domain
- mcnairfinancial.com
Victim entity
- Name
- McNair & Companynorm: mcnair
- Domain
- mcnairfinancial.com
Incident
- Discovered
- May 12, 2021
- Materiality determined
- —
- Notification sent
- Aug 27, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.