Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Brady Sullivan Properties
bd_b4e91c1f9a18f231 · schema v1 · pii pii-v1
Full breach record for Brady Sullivan Properties →Brady Sullivan Properties (BSP), a New Hampshire real estate developer, notified the NH Attorney General of a data security incident involving unauthorized access to two employee email accounts between September and October 2020. The breach affected 11 individuals (9 NH residents), exposing names, SSNs, and financial account info. BSP engaged forensic investigators, secured email systems, implemented MFA, and offered credit monitoring via IDX. Notifications were sent on April 7, 2021.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed11 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/brady-sullivan-properties-20210407.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2021
- Raw hash
- a1b3a4adab5b2e53f0b03f91f409708ddc992b6103eeed6d5641b614045ccbdc
Reporting entity
- Name
- Brady Sullivan Propertiesnorm: brady sullivan properties
Victim entity
- Name
- Brady Sullivan Propertiesnorm: brady sullivan properties
Incident
- Discovered
- Oct 31, 2020
- Materiality determined
- —
- Notification sent
- Apr 7, 2021
- Affected individuals
- 11
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Gordon MacDonald
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(158 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.