Social EngineeringPhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
M & M Excavating, LLC
bd_af453be393632849 · schema v1 · pii pii-v1
Full breach record for M & M Excavating, LLC →M&M Excavating, Inc. notified the New Hampshire Attorney General of a security incident discovered on November 9, 2022. An employee's email account was compromised via phishing, leading to unauthorized ACH payments. Personal information (names, SSNs, driver's license numbers) of 5 NH residents was accessed. Notifications were mailed on January 9, 2023, with credit monitoring offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/m-m-excavating-20230110.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 10, 2023
- Raw hash
- abf64229072bb2901e84450fa6e425c54f63aa091ee01c3346f7a61c529dcef8
Reporting entity
- Name
- M & M Excavating, LLCnorm: m m excavating
Victim entity
- Name
- M & M Excavating, LLCnorm: m m excavating
Incident
- Discovered
- Nov 9, 2022
- Materiality determined
- Dec 20, 2022
- Notification sent
- Jan 9, 2023
- Affected individuals
- 5
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.