Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Cast-Crete USA, LLC
bd_9f7d9f905b40364a · schema v1 · pii pii-v1
Full breach record for Cast-Crete USA, LLC →Cast-Crete USA, Inc. notified New Hampshire residents of a cyber incident detected on April 5, 2023, involving unauthorized access to an email account. The breach potentially exposed names and addresses of 1 New Hampshire resident and 2 Rhode Island residents. The company offered 12 months of credit monitoring via Experian and implemented additional employee safeguards.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cast-crete-usa-20231222.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2023
- Raw hash
- b64e9cde91900e639f8b079833a062222c6b2c85cdd2049513949a93240fd044
Reporting entity
- Name
- Cast-Crete USA, LLCnorm: cast crete usa
Victim entity
- Name
- Cast-Crete USA, LLCnorm: cast crete usa
Incident
- Discovered
- Apr 5, 2023
- Materiality determined
- Oct 20, 2023
- Notification sent
- Dec 22, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified relevant state regulatorsNotified the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- phishing_link
Compliance
- Time to disclose
- 37 weeks(261 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.