Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
United Steelworkers Local 286
bd_8ff5f5f8279c1641 · schema v1 · pii pii-v1
Full breach record for United Steelworkers Local 286 →United Steelworkers Local 286 notified the NH AG that an unauthorized party accessed an employee email account between June 16 and July 18, 2022. The breach was discovered on Feb 13, 2023, affecting 13 NH residents with PII including SSNs and medical info. The union secured the account, engaged forensic experts, and offered credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3a7047a9b8704fceMontana State AGfiled 2023-04-30(9d gap)Candidate
- bd_df9455cea46f7175Maine State AGfiled 2023-04-30(9d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/united-steelworkers-local-286-20230509.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 9, 2023
- Raw hash
- 94f54110cd963317208a07dc1d85ae4a62eabf643683d664e81d7cc109d9c015
Reporting entity
- Name
- United Steelworkers Local 286norm: united steelworkers local 286
Victim entity
- Name
- United Steelworkers Local 286norm: united steelworkers local 286
Incident
- Discovered
- Feb 13, 2023
- Materiality determined
- —
- Notification sent
- Apr 14, 2023
- Affected individuals
- 13
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.