DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingEmployee Data InvolvedTargetedIdentity (basic)Government IDEmploymentMediumContained

O.C. Tanner

bd_b6c8327ade54d00e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 14, 2016

Filed

Apr 26, 2016

To disclose

12 days

Affected

2state residents only

Linked

2 filings

Confidence

65%
Full breach record for O.C. Tanner2 incidents on file

O.C. Tanner experienced a targeted email phishing attack on April 14, 2016, resulting in the unauthorized disclosure of 2015 W-2 tax form information for employees. The compromised data included names, addresses, Social Security numbers, and wage information. The company discovered the incident on the same day and began notifying affected individuals via email on April 15, 2016. Two New Hampshire residents were affected. O.C. Tanner notified the FBI and IRS, and offered one year of credit monitoring to affected employees.

Incident timeline

discovery → filing · 12 days

Apr 14, 2016

Begins

Apr 14, 2016

Discovered

Apr 26, 2016

Filed

vs. sector median

17 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Montana State AGApr 15 · first
New Hampshire State AG+11d · this page

Pattern: first filing Apr 15 (MT), last Apr 26 (NH) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.