Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Anderson & Murison, Inc.
bd_f6c2412bc4bd4468 · schema v1 · pii pii-v1
Full breach record for Anderson & Murison, Inc. →Anderson & Vreeland, Inc. notified the New Hampshire Attorney General of a phishing incident affecting three NH residents. Unauthorized access to employee email accounts occurred from Jan 9, 2018 to Feb 28, 2018. Personal information (names, SSNs, driver's license numbers) was accessed. Notifications were mailed on June 28, 2018, offering one year of Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/anderson-20180628.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 28, 2018
- Raw hash
- 841983f7c0e3bbd1d2efdccdc35f6cb016cc32a7408a760eac302dd8f6e3e76f
Reporting entity
- Name
- BAKER & HOSTETLER LLPnorm: baker hostetler
Victim entity
- Name
- Anderson & Murison, Inc.norm: anderson murison
Incident
- Discovered
- Apr 24, 2018
- Materiality determined
- —
- Notification sent
- Jun 28, 2018
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.