Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
Blakehurst
bd_e8bf561dd84863fb · schema v1 · pii pii-v1
Full breach record for Blakehurst →Blakehurst, a senior living community, notified the NH AG of a data security incident discovered on Feb 7, 2022. Unauthorized access to employee email accounts occurred, potentially exposing PII, SSNs, financial data, and PHI of residents. Notices were mailed on Dec 6, 2022. No evidence of misuse was found.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_63ebb36be85dfb35Montana State AGfiled 2022-12-06(1d gap)Candidate
- bd_6fa59eb2cb19291eHHS OCRfiled 2022-12-06(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/blakehurst-20221207.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 7, 2022
- Raw hash
- 712f47a53365ae02a1aa51978e03217f49c427d5a3ea73a5b078fabfbec16f09
Reporting entity
- Name
- Blakehurstnorm: blakehurst
Victim entity
- Name
- Blakehurstnorm: blakehurst
Incident
- Discovered
- Feb 7, 2022
- Materiality determined
- Aug 5, 2022
- Notification sent
- Dec 6, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 43 weeks(303 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.