Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICLowContained
Hafetz and Associates
bd_99825a14fdb86b67 · schema v1 · pii pii-v1
Full breach record for Hafetz and Associates →Hafetz & Associates notified the NH Attorney General of a phishing incident resulting in unauthorized access to employee email accounts between July 24 and October 12, 2023. One NH resident's name was exposed. Hafetz blocked access, investigated, and mailed notifications on June 28, 2024, offering two years of credit monitoring via Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0af1dc0c1c4bed80Indiana State AGfiled 2024-06-28Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hafetz-associates-20240628.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 28, 2024
- Raw hash
- 0a04fa0841d5bb372a34ffc8901944cd7447880cddbf3a6ce3c5ade2a58d544e
Reporting entity
- Name
- Hafetz and Associatesnorm: hafetz and associates
Victim entity
- Name
- Hafetz and Associatesnorm: hafetz and associates
Incident
- Discovered
- Oct 12, 2023
- Materiality determined
- —
- Notification sent
- Jun 28, 2024
- Affected individuals
- 1
- Data types
- IDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- phishing_link
Compliance
- Time to disclose
- 37 weeks(260 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.