Social EngineeringPhishingCustomer Data InvolvedCREDENTIALSPIILowContained
Integral Federal Inc.
bd_bae8f3126052e2b8 · schema v1 · pii pii-v1
Full breach record for Integral Federal Inc. →Integral Federal Inc. notified New Hampshire residents on April 25, 2024, regarding a cybersecurity incident involving unauthorized access to employee email accounts. The breach occurred between February 11, 2023, and March 30, 2023, after suspicious activity was detected on March 24, 2023. Approximately five New Hampshire residents were notified. The incident involved credential compromise via phishing, potentially exposing PII. Integral Federal secured accounts, launched an investigation, and offered 24 months of credit monitoring through Experian.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_196c2761a331dbabVermont State AGfiled 2024-04-25Verified
- bd_28ad276a2b83a969Indiana State AGfiled 2024-04-25Verified
- bd_612f0c0ada1d2710Montana State AGfiled 2024-04-25Candidate
- bd_82625411e9315de1Maine State AGfiled 2024-04-25Verified
Show 1 more filing ↓Show fewer ↑up to 69d gap
- bd_9ba8ae660b6b5a7dVermont State AGfiled 2024-07-03(69d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/integral-federal-20240425.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2024
- Raw hash
- 596c55db1d84a63e452a3b0a946aa9908e06b4e69052efe4eda0678644f7ed74
Reporting entity
- Name
- Integral Federal Inc.norm: integral federal
Victim entity
- Name
- Integral Federal Inc.norm: integral federal
Incident
- Discovered
- Mar 24, 2023
- Materiality determined
- —
- Notification sent
- Apr 25, 2024
- Affected individuals
- 5
- Data types
- CREDENTIALSPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Provided written notice of this incident to relevant state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 months(398 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.