Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Grandfield & Dodd, LLC
bd_dd5d7db88101cbb3 · schema v1 · pii pii-v1
Full breach record for Grandfield & Dodd, LLC →Grandfield & Dodd, LLC reported unauthorized access to an employee's email account between Oct 19-20, 2022. The attacker likely gained access via phishing. The breach exposed names and Social Security numbers of affected individuals. The firm engaged a cybersecurity firm, secured the account, and is offering one year of credit monitoring and identity protection services through IDX.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4966f62f5c5e4e67Maine State AGfiled 2023-02-24Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/grandfield-dodd-20230224.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2023
- Raw hash
- 8fbf7b1ec482d94670b35c2f0b8bd72a9c4f50705e0807b25aff03fd5913e774
Reporting entity
- Name
- Grandfield & Dodd, LLCnorm: grandfield dodd
Victim entity
- Name
- Grandfield & Dodd, LLCnorm: grandfield dodd
Incident
- Discovered
- Oct 20, 2022
- Materiality determined
- Jan 25, 2023
- Notification sent
- Feb 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.