Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
American Association of Colleges of Osteopathic Medicine
bd_d68c22df129ea118 · schema v1 · pii pii-v1
Full breach record for American Association of Colleges of Osteopathic Medicine →AACOM notified the NH AG of a data security incident discovered on Sept 26, 2024, involving unauthorized access to an employee email account via phishing. 259 NH residents were affected. AACOM engaged forensic experts, secured its email environment, and provided 12 months of credit monitoring and identity protection services to affected individuals.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0f81799057ac7a06Indiana State AGfiled 2025-04-08Verified
- bd_31778ded704f2f6dIowa State AGfiled 2025-04-08Candidate
- bd_6ab7b871b501d6bdVermont State AGfiled 2025-04-08Verified
- bd_dab067214f98a919Oregon State AGfiled 2025-04-08Verified
Show 3 more filings ↓Show fewer ↑
- bd_e8b87fa5585fb708California State AGfiled 2025-04-08Verified
- bd_ebcca748e75e0a1fMaine State AGfiled 2025-04-08Verified
- bd_f350f7480c2e9683Washington State AGfiled 2025-04-08Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/american-association-colleges-osteopathic-medicine-20250408.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2025
- Raw hash
- 3ca2eede879428f02a81811b3274ea97b648326f5595295143e76fa5d1754735
Reporting entity
- Name
- American Association of Colleges of Osteopathic Medicinenorm: american association of colleges of osteopathic medicine
Victim entity
- Name
- American Association of Colleges of Osteopathic Medicinenorm: american association of colleges of osteopathic medicine
Incident
- Discovered
- Sep 26, 2024
- Materiality determined
- Mar 31, 2025
- Notification sent
- Apr 8, 2025
- Affected individuals
- 259
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 weeks(194 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.