Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Kerecis LLC
bd_9ae4c3ac122e06c4 · schema v1 · pii pii-v1
Full breach record for Kerecis LLC →Kerecis LLC notified the NH Attorney General of a security incident affecting current and former employees. The breach, occurring on Feb 24, 2023, was detected on March 29, 2023, after the IRS identified employees as identity theft victims. The cause was a social engineering scheme, not a system hack. One NH resident was affected. Kerecis engaged law enforcement, initiated its incident response plan, and offered 2 years of identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kerecis-20230504.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 4, 2023
- Raw hash
- f10a860c2883df9de6742cb9cb62eac694745ed3eba83ad55c458e38673e8cd5
Reporting entity
- Name
- Kerecis LLCnorm: kerecis
Victim entity
- Name
- Kerecis LLCnorm: kerecis
Incident
- Discovered
- Mar 29, 2023
- Materiality determined
- —
- Notification sent
- May 2, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement and will assist them in their investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.