DisclosureLens
Social EngineeringManufacturingManufacturingPhishingTargetedIdentity (basic)Government IDFinancial accountPIIMediumContained

Rite-Hite Holding Corporation

bd_d66f1591dec58380 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 21, 2022

Filed

Jul 20, 2022

To disclose

29 days

Affected

1state residents only

Linked

2 filings

Confidence

66%
Full breach record for Rite-Hite Holding Corporation

Rite-Hite Holding Corporation notified Montana residents of a phishing attack on a user's email account on May 4, 2022. The investigation discovered on June 21, 2022 that the account contained documents with personal information including names, SSNs, driver's licenses, passport numbers, financial account info, and payment card data. Rite-Hite disabled the account, changed passwords, and offered 12 months of credit monitoring.

Incident timeline

undetected · 48 days
discovery → filing · 29 days

May 4, 2022

Begins

Jun 21, 2022

Discovered

Jul 20, 2022

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Indiana State AGJul 20 · first
Montana State AGJul 20 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.