Houghton Mifflin Harcourt Company
bd_c052ff7000a09020 · schema v1 · pii pii-v1
Full breach record for Houghton Mifflin Harcourt Company →Houghton Mifflin Harcourt (HMH) notified the New Hampshire Attorney General on July 1, 2008, regarding a worldwide Internet-based attack on a non-e-commerce website discovered on April 25, 2008. The incident compromised Social Security Numbers for approximately 194 individuals, including 2 New Hampshire residents. HMH retained digital forensics experts, reported the matter to the U.S. Secret Service and state law enforcement, and arranged for two years of free credit monitoring and identity theft insurance for affected individuals. The investigation was ongoing at the time of filing.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/wilmerhale-20080701.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2008
- Raw hash
- 263ace93ae2a944110ff54cc71ebc396f1dae9c35b2c9f271dc06eef82b5831c
Reporting entity
- Name
- WILMER CUTLER PICKERING HALE AND DORR LLPnorm: wilmer cutler pickering hale and dorr
Victim entity
- Name
- Houghton Mifflin Harcourt Companynorm: houghton mifflin harcourt
- Domain
- hmhco.com
Incident
- Discovered
- Apr 25, 2008
- Materiality determined
- —
- Notification sent
- Jul 1, 2008
- Affected individuals
- 194
- Data types
- IDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported this matter to the U.S. Secret Service and state law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.