Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
HD Vest Investment Services (2)
bd_e83b554b0e1ed668 · schema v1 · pii pii-v1
Full breach record for HD Vest Investment Services (2) →HD Vest Investment Services notified the New Hampshire Attorney General of a phishing incident affecting 2 state residents. An advisor received a malicious message on July 28, 2016, granting an attacker remote access to her computer until August 1, 2016. The attacker potentially accessed customer PII, including SSNs. HD Vest notified residents on October 4, 2016, and offered credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fc93354e20de9c23Montana State AGfiled 2016-10-05Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hd-vest-investment-20161005.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2016
- Raw hash
- 3fad1001202d1e63212da0b7942f789cb382bd0ca0bbfff9e338406b068dff3d
Reporting entity
- Name
- BAKER & HOSTETLER LLPnorm: baker hostetler
Victim entity
- Name
- HD Vest Investment Services (2)norm: hd vest investment services 2
Incident
- Discovered
- Aug 1, 2016
- Materiality determined
- —
- Notification sent
- Oct 4, 2016
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.