Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICLowContained
Loomis U.S.
bd_c92f880e531b025c · schema v1 · pii pii-v1
Full breach record for Loomis U.S. →Loomis Chaffee School reported a phishing incident where unauthorized parties accessed employee email accounts between Oct 10-27, 2024. The school detected the incident on Oct 25, 2024, secured accounts, and engaged forensic investigators. Notification letters were mailed on Feb 18, 2025, to 3 NH residents, offering credit monitoring. PII was accessed via email.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/loomis-chaffee-school-20250218.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 18, 2025
- Raw hash
- 450a3ce4b145ee0fd7fd89bb5bb1907974ca35e5c408debcd338071be45b946f
Reporting entity
- Name
- The Loomis Chaffee Schoolnorm: the loomis chaffee school
Victim entity
- Name
- Loomis U.S.norm: loomis us
- Domain
- loomis.us
Incident
- Discovered
- Oct 25, 2024
- Materiality determined
- Jan 10, 2025
- Notification sent
- Feb 18, 2025
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.