Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Hoshino (USA) Inc.
bd_bbaab3d513f3f88e · schema v1 · pii pii-v1
Full breach record for Hoshino (USA) Inc. →Hoshino (U.S.A.) Inc. notified the New Hampshire AG of unauthorized access to two employee email accounts between June-August 2024. The breach likely resulted from phishing, compromising valid credentials. Approximately one NH resident's PII was potentially exposed. Hoshino secured accounts, investigated, notified individuals, and provided credit monitoring via IDX.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hoshino-20250403.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2025
- Raw hash
- fbc6edeabfce049a36a04eff5adc0377b976a168ec05fa8f146878998f674f08
Reporting entity
- Name
- Hoshino (USA) Inc.norm: hoshino usa
- Domain
- hoshinousainfo.com
Victim entity
- Name
- Hoshino (USA) Inc.norm: hoshino usa
- Domain
- hoshinousainfo.com
Incident
- Discovered
- Aug 5, 2024
- Materiality determined
- —
- Notification sent
- Apr 3, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 34 weeks(241 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.