Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
MountainOne
bd_c982f045f09c1ace · schema v1 · pii pii-v1
Full breach record for MountainOne →MountainOne notified the NH Attorney General of unauthorized access to two employee email accounts between July 29 and August 10, 2022. The incident involved phishing leading to credential compromise. Data of 10 NH residents was exposed, including names, SSNs, driver's license numbers, and financial account numbers. MountainOne engaged forensic investigators, secured accounts, and offered one year of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_cffdd270fbaaf2e4Montana State AGfiled 2022-12-09Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mountainone-20221209.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 9, 2022
- Raw hash
- 68ff7f2410236928c87f81597da4e04cca57f14da256c1f6e61c4fd2ed091f4e
Reporting entity
- Name
- MountainOnenorm: mountainone
Victim entity
- Name
- MountainOnenorm: mountainone
Incident
- Discovered
- Jul 29, 2022
- Materiality determined
- Nov 4, 2022
- Notification sent
- Dec 9, 2022
- Affected individuals
- 10
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.