The Republican Governors Association
bd_e40fa04553cd585a · schema v1 · pii pii-v1
Full breach record for The Republican Governors Association →The Republican Governors Association (RGA) notified the New Hampshire Attorney General of a data breach involving 4 state residents. Threat actors exploited a vulnerability in Microsoft Exchange Server to access RGA's email environment between February and March 2021. While forensic investigators could not confirm what specific data was accessed, the breach notification letter indicates that some residents' names, Social Security numbers, or payment card information may have been accessible. RGA implemented Microsoft patches, offered two years of credit monitoring, and notified the FBI and state regulators.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d1b4faf7253b34b8Montana State AGfiled 2021-09-15Candidate
- bd_fa1f241ce4f24905Maine State AGfiled 2021-09-15Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/republican-governors-association-20210915.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2021
- Raw hash
- 6ec9b789d4284e830cfa8e47cb5dbfe7ad3b61bd37c95a3fad1a2a220c114dc9
Reporting entity
- Name
- FOX ROTHSCHILD LLPnorm: fox rothschild
- Domain
- foxrothschild.com
Victim entity
- Name
- The Republican Governors Associationnorm: the republican governors
Incident
- Discovered
- Mar 10, 2021
- Materiality determined
- —
- Notification sent
- Sep 15, 2021
- Affected individuals
- 4
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- provided notice of this incident to other state regulators and the consumer reporting agenciesnotified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.