Social EngineeringPhishingStolen CredentialsTargetedIDENTITY_BASICCREDENTIALSLowContained
STG International, Inc.
bd_ac0a142e2031c9de · schema v1 · pii pii-v1
Full breach record for STG International, Inc. →STG International, Inc. reported a phishing campaign targeting employee email accounts between October 2020 and January 2021. Unauthorized access was gained, potentially exposing personal information. STG reset credentials, enforced MFA, and provided 12 months of identity monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_924b9feaf7528b7dMaine State AGfiled 2021-06-16Verified
- bd_15cc917dea0457f7New Hampshire State AGfiled 2021-06-21(5d gap)Verified
- bd_23882a1770cf6475Montana State AGfiled 2021-06-02(14d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541931
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 16, 2021
- Raw hash
- cdba6db9effaf951dd57ea89cc7e2b7d61f9db410a3e3c10902aad86263ae9a8
Reporting entity
- Name
- STG International, Inc.norm: stg international
Victim entity
- Name
- STG International, Inc.norm: stg international
Incident
- Discovered
- May 3, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.