Boulos Asset Mgmt
bd_d0da4760cd70ca01 · schema v1 · pii pii-v1
Full breach record for Boulos Asset Mgmt →The Boulos Company notified the New Hampshire Attorney General on July 9, 2021, of a ransomware incident detected on March 30, 2021. An unauthorized party attempted to lock the company out of its network for financial payment. The company shut off network access and engaged forensic investigators. The investigation determined that the full name, mailing address, and Social Security number of three New Hampshire residents may have been compromised. No evidence of data misuse was found. The company notified the affected individuals on June 29, 2021, and offered 18 months of credit monitoring through Kroll. Remediation included MFA, updated security programs, and secure file transfer systems.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/boulos-20210709.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 9, 2021
- Raw hash
- 8759bf62104a19229df03b9f6334af638d6201317f4c2d5c17883ccdc4d15342
Reporting entity
- Name
- Boulos Asset Mgmtnorm: boulos asset mgmt
- Domain
- boulospm.com
Victim entity
- Name
- Boulos Asset Mgmtnorm: boulos asset mgmt
- Domain
- boulospm.com
Incident
- Discovered
- Mar 30, 2021
- Materiality determined
- —
- Notification sent
- Jun 29, 2021
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(101 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.