Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Laughton Co.
bd_9bf888b90c822d6d · schema v1 · pii pii-v1
Full breach record for The Laughton Co. →The Laughton Co. notified the Idaho Attorney General of a security incident on January 24, 2025, where an employee's email account was compromised via phishing. The attacker sent fraudulent emails as the employee. The company engaged Kroll for identity monitoring services and restored mailbox control with MFA enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/02/2-21-2025-The-Laughton-Co.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2025
- Raw hash
- 3f72187f20ac505d7029a6d1d4c562d9ae95744b8e4da28d9a54ac761b7737e0
Reporting entity
- Name
- The Laughton Co.norm: the laughton
Victim entity
- Name
- The Laughton Co.norm: the laughton
Incident
- Discovered
- Jan 24, 2025
- Materiality determined
- —
- Notification sent
- Feb 24, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.