Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Community Phone Company
bd_db049a370753560b · schema v1 · pii pii-v1
Full breach record for Community Phone Company →Wallace Murry Phone Company (dba Community Phone) notified the NH Attorney General on August 14, 2025, of a breach affecting 18 NH residents. On July 2, 2025, phishing emails prompted employees to provide credentials, granting an unauthorized actor access to a third-party contractor's account used for call recordings. The actor accessed call transcripts containing names, payment info, and bank details. Notices were sent to affected individuals on August 5, 2025.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1665e362bab73e81Maine State AGfiled 2025-08-13(1d gap)Candidate
- bd_1aaa56bcaa58c615Montana State AGfiled 2025-08-13(1d gap)Verified
- bd_5441a4c369c7e7adIndiana State AGfiled 2025-08-01(13d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/wallace-murry-phone-community-20250814.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2025
- Raw hash
- bec80ba024f5740223f5831ad6fdc344d2da0c128e73bc733761d231ffae9280
Reporting entity
- Name
- Community Phone Companynorm: community phone
- Domain
- communityphone.org
Victim entity
- Name
- Community Phone Companynorm: community phone
- Domain
- communityphone.org
Incident
- Discovered
- Jul 2, 2025
- Materiality determined
- —
- Notification sent
- Aug 5, 2025
- Affected individuals
- 18
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.