MisusePrivilege AbuseEmployee Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHighResolved
Fannie Mae
bd_e4de68eaeadac101 · schema v1 · pii pii-v1
Full breach record for Fannie Mae →Fannie Mae notified the New Hampshire Attorney General on October 28, 2011, regarding a security incident involving approximately 1,100 individuals. In mid-October 2011, the company became aware that an employee may have been attempting to sell handwritten copies of financial information, including names, addresses, Social Security numbers, dates of birth, and credit scores. Fannie Mae notified the NH AG and sent letters to the affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,100 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/fannie-mae-20111028.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 28, 2011
- Raw hash
- fd9f966c08a7b49da9a165ae4f96370f2248e32accd7b4ac914a3bc9faae0911
Reporting entity
- Name
- Fannie Maenorm: fannie mae
Victim entity
- Name
- Fannie Maenorm: fannie mae
Incident
- Discovered
- Oct 15, 2011
- Materiality determined
- —
- Notification sent
- Oct 28, 2011
- Affected individuals
- 1,100
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- insider_action
Compliance
- Time to disclose
- 13 days(13 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.