Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTAUTHENTICATIONMediumContained
Foster + Partners
bd_e81cf3e812cf66b8 · schema v1 · pii pii-v1
Full breach record for Foster + Partners →Foster LLP, a law firm, notified the New Hampshire Attorney General of a data security incident involving unauthorized access to a corporate email account. An unauthorized user accessed the account for two days (Feb 3-5, 2021) likely via phishing. The breach potentially exposed names, SSNs, driver's licenses, passport numbers, financial/credit card info, and biometric data of 2 New Hampshire residents. Foster changed passwords, implemented security controls, and provided 12 months of credit monitoring via IDX.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/foster-20210930.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 30, 2021
- Raw hash
- 21f21a6884235f7aadbba910b3d4b8db7c2083b3fa39fd0ac1c701a37962e6dd
Reporting entity
- Name
- Foster + Partnersnorm: foster partners
- Domain
- fosterandpartners.com
Victim entity
- Name
- Foster + Partnersnorm: foster partners
- Domain
- fosterandpartners.com
Incident
- Discovered
- Feb 3, 2021
- Materiality determined
- —
- Notification sent
- Sep 30, 2021
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 34 weeks(239 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.