DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDFinancial accountMediumContained

The Richards Group

bd_f104fa17a92db6d5 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 3, 2019

Filed

Feb 25, 2019

To disclose

8 weeks

Affected

22state residents only

Confidence

66%
Full breach record for The Richards Group3 incidents on file

The Richards Group notified the NH AG of a phishing attack targeting an employee's email account from April 17, 2018 to October 1, 2018. The firm discovered the breach on January 3, 2019. Approximately 22 NH residents were affected, with their names, SSNs, driver's licenses, and/or bank account info exposed. The company engaged forensic investigators, notified residents on Feb 15, 2019, and offered credit monitoring.

Incident timeline

undetected · 261 days
discovery → filing · 8 weeks / 53 days

Apr 17, 2018

Begins

Jan 3, 2019

Discovered

Feb 25, 2019

Filed

vs. sector median

10 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed22 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.