Social EngineeringPhishingStolen CredentialsBECMulti-Stage ChainWire FraudCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Curtis & Croft, LLC
bd_c139569371b869c4 · schema v1 · pii pii-v1
Full breach record for Curtis & Croft, LLC →Curtis & Croft, LLC, a South Carolina law firm, reported a business email compromise incident discovered on September 2, 2022. An unauthorized party gained access to a business email account, likely to facilitate wire fraud. The incident potentially exposed clients' names and Social Security numbers found in real estate closing documents. The firm engaged forensic specialists, secured the email environment, and offered 12 months of credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/curtis-croft-20230309.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2023
- Raw hash
- 9200ed456e39abb3aa8cc55d3820256d4bd5cc5f971b7c256a47fb883fac82e3
Reporting entity
- Name
- Curtis & Croft, LLCnorm: curtis croft
Victim entity
- Name
- Curtis & Croft, LLCnorm: curtis croft
Incident
- Discovered
- Sep 2, 2022
- Materiality determined
- —
- Notification sent
- Mar 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 weeks(188 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.