Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Clement Auto Group
bd_c695c71839e5d4b8 · schema v1 · pii pii-v1
Full breach record for Clement Auto Group →Copeland Auto Group notified the NH AG of a phishing incident on Sept 2, 2025, compromising one employee email account. Data exposed included names, SSNs, driver's licenses, passports, payment card info, financial accounts, and health info. One NH resident notified on Oct 16, 2025. Remediation included MFA and forensic investigation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/copeland-auto-20251022.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 22, 2025
- Raw hash
- 06db8107e3ca6cc1e3618ea1dfb13a565dbacf9980f4e1db7cfc407a3f003452
Reporting entity
- Name
- Clement Auto Groupnorm: clement auto
- Domain
- clementautogroup.com
Victim entity
- Name
- Clement Auto Groupnorm: clement auto
- Domain
- clementautogroup.com
Incident
- Discovered
- Sep 2, 2025
- Materiality determined
- —
- Notification sent
- Oct 16, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.