Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Igoe
bd_cfc4291435540310 · schema v1 · pii pii-v1
Full breach record for Igoe →Igoe & Company Incorporated, an employee benefits administrator, notified the New Hampshire Attorney General of a data event affecting one NH resident. Unauthorized access to a business partner's email account occurred between Feb 25 and Mar 11, 2020. The email contained names and Social Security numbers. Igoe engaged forensic specialists, reviewed the account, and provided one year of credit monitoring to the affected individual. Remediation included enhanced security training, MFA, and email security upgrades.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/igoe-company-20210302.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2021
- Raw hash
- 97b16f241a42c83fa9243c8bbbe4f296fddab4e1df4f91a1fa58c9bd4e197312
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Igoenorm: igoe
- Domain
- goigoe.com
Incident
- Discovered
- Mar 11, 2020
- Materiality determined
- —
- Notification sent
- Sep 25, 2020
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 51 weeks(356 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.