Gannett Company, Inc.
bd_b7d86566afd376bf · schema v1 · pii pii-v1
Full breach record for Gannett Company, Inc. →3 incidents on fileGannett Company, Inc. notified the NH AG of a phishing attack on March 30, 2017, compromising HR Office 365 credentials. Perpetrators sent further phishing emails and attempted a fraudulent wire transfer (unsuccessful). 18,100 individuals affected, including 3 NH residents. Data potentially exposed: names, SSNs, DOB, bank/routing numbers, salary info. Gannett locked accounts, conducted forensic investigation, notified FBI, and provided 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 30, 2017
Discovered
Apr 28, 2017
Filed
vs. sector median
15 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_2f5e4908de2fddea2017-04-28Candidate
- Massachusetts State AGbd_61e7bc23c2170e6b2017-04-28Verified
- California State AGbd_7f12b327f14904e72017-04-28Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.