Social EngineeringPhishingBECMulti-Stage ChainData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASICMediumActive
PlanMember Financial
bd_dd862f39ba8fd8b6 · schema v1 · pii pii-v1
Full breach record for PlanMember Financial →PlanMember Securities Corporation reported a cybersecurity event to the NH Attorney General on April 11, 2022. On Feb 17, 2022, the CFO clicked a phishing link, compromising his email account. Attackers used the credentials to attempt Business Email Compromise (BEC) fraud starting March 15, 2022. The incident involved access to employee and client PII (SSNs, account numbers). 16 NH residents are potentially affected. Investigation is ongoing.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_59916b7518e7d686California State AGfiled 2022-04-15(4d gap)Candidate
- bd_be1890f84a353419Washington State AGfiled 2022-04-15(4d gap)Verified
- bd_bf5c1abaa9187ec6Oregon State AGfiled 2022-04-15(4d gap)Verified
- bd_a44fc4621a30a1b2Maine State AGfiled 2022-06-27(77d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 81d gap
- bd_58d9e5f0a778fdd4California State AGfiled 2022-06-29(79d gap)Verified
- bd_a4b2b687e3b8e7c1Montana State AGfiled 2022-07-01(81d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/planmember-securities-20220411.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2022
- Raw hash
- b709200826f3e9659132d4d355f5d07d2c556595993a5d61f1e4541d71d5a341
Reporting entity
- Name
- PlanMember Financialnorm: planmember financial
- Domain
- planmember.com
Victim entity
- Name
- PlanMember Financialnorm: planmember financial
- Domain
- planmember.com
Incident
- Discovered
- Mar 15, 2022
- Materiality determined
- Mar 30, 2022
- Notification sent
- Apr 11, 2022
- Affected individuals
- 16
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- submitting this notice to provide the New Hampshire Attorney General with information regarding a suspected cybersecurity event
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.