HackingStolen CredentialsPhishingTargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Komatsu America Corp.
bd_fe1aacb9ca143992 · schema v1 · pii pii-v1
Full breach record for Komatsu America Corp. →Komatsu America Corp. notified the New Hampshire Attorney General of a cybersecurity incident discovered on September 22, 2021. An unauthorized external actor used stolen credentials to access an employee's email account between September 20 and 22, 2021. The actor bypassed MFA and created malicious rules to hide inbound messages. While no evidence suggested data was accessed, the account contained PII, SSNs, and financial info. Two NH residents were notified on December 6, 2021, and offered 12 months of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_076fbb8f08f92a74Maine State AGfiled 2021-12-06Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/komatsu-america-20211206.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2021
- Raw hash
- 4fa27ac7fafbfee6bf3296827f1e2b9975f1b0a5418bb24756378dfaae3430c7
Reporting entity
- Name
- Komatsu America Corp.norm: komatsu america
Victim entity
- Name
- Komatsu America Corp.norm: komatsu america
Incident
- Discovered
- Sep 22, 2021
- Materiality determined
- —
- Notification sent
- Dec 6, 2021
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.