Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Everest Global Services, Inc
bd_c66e06e07833730f · schema v1 · pii pii-v1
Full breach record for Everest Global Services, Inc →Everest Global Services, Inc. reported unauthorized access to five email accounts between August 8-16, 2022, following suspicious activity detected on August 15, 2022. The incident involved phishing leading to credential compromise. PII of 7 New Hampshire residents was affected, including names, SSNs, driver's licenses, financial account info, and PHI. Everest engaged forensic experts, reset passwords, enhanced MFA, and offered credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b4d427d811c2e3ecMontana State AGfiled 2022-12-16(3d gap)Candidate
- bd_cb49d4b24eef8f8eOregon State AGfiled 2022-12-16(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/everest-global-services-20221219.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2022
- Raw hash
- 7110aaf5f958be3c4f9a43a83f40f106e651846bfd4155a99af0ed6a1cc56345
Reporting entity
- Name
- Everest Global Services, Incnorm: everest global
Victim entity
- Name
- Everest Global Services, Incnorm: everest global
Incident
- Discovered
- Aug 15, 2022
- Materiality determined
- Oct 10, 2022
- Notification sent
- Dec 16, 2022
- Affected individuals
- 7
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.