Social EngineeringPhishingCustomer Data InvolvedTargetedCREDENTIALSIDENTITY_BASICLowActive
Quixtar Inc.
bd_d0af5ce1eb2088ed · schema v1 · pii pii-v1
Full breach record for Quixtar Inc. →Quixtar Inc. notified New Hampshire Attorney General Kelly Ayotte of a security incident discovered on May 27, 2008. Fraudsters accessed Independent Business Owner (IBO) accounts using credentials obtained from an external website (phishing). The intruders changed bank account details to divert bonus payments. Quixtar scrambled passwords on June 4, 2008, and sent notification letters on June 11, 2008. No SSN, credit card, or bank account numbers were accessed. Quixtar cooperated with the FBI. The investigation was active as of the filing date.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/quixtar-20080611.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2008
- Raw hash
- 99440fed074307c3897ca1e08f567ff7ac948d6f3377a3e3b1521b8b87f28703
Reporting entity
- Name
- Quixtar Inc.norm: quixtar
Victim entity
- Name
- Quixtar Inc.norm: quixtar
Incident
- Discovered
- May 27, 2008
- Materiality determined
- —
- Notification sent
- Jun 11, 2008
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI about the incident and is cooperating in the FBI's investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.