HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALMediumContained
USG Insurance Services
bd_911486c7519a39a4 · schema v1 · pii pii-v1
Full breach record for USG Insurance Services →USG Insurance Services, Inc. notified the New Hampshire Attorney General of a cybersecurity incident discovered on October 27, 2020. An unauthorized user gained access to a server storing employee PII, potentially affecting 5 NH residents. Data accessed included names, SSNs, driver's licenses, and financial info. USG engaged forensic investigators, implemented Carbon Black security measures, reset passwords, and provided 12 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6624db252d4535fcMaine State AGfiled 2020-11-25(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/usg-insurance-services-20201130.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2020
- Raw hash
- dc60f8a1b90edf529efd2830b1e8c05fd95cf46927903607309d209af4770127
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- USG Insurance Servicesnorm: usg insurance
Incident
- Discovered
- Oct 27, 2020
- Materiality determined
- —
- Notification sent
- Nov 25, 2020
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.