Phase II Systems
ent_ec39e070955eb3353fdba6e3
Disclosures
5
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,170
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Phase II Systems
- Normalized
- phase ii— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- New Hampshire State AGas victim2024-09-03
Phase II Systems d/b/a PARS notified the New Hampshire Attorney General of a phishing incident where an unauthorized party accessed an employee's email account between March 11-14, 2024. PARS discovered the compromise on August 1, 2024, affecting approximately 2 New Hampshire residents. PII included names and government IDs. PARS secured the account, engaged forensic investigators, and offered credit monitoring.
- Massachusetts State AGas victim2024-09-03
Phase II Systems d/b/a PARS reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-09-03. 5 Massachusetts residents were affected.
- California State AGas victim2024-08-29
Phase II Systems d/b/a PARS experienced a phishing incident where an unauthorized party accessed an employee's email account between March 11 and March 14, 2024. The compromised account contained personal information including full names and Social Security numbers. The company secured the account, engaged external cybersecurity professionals, and is offering credit monitoring to affected individuals.
- Indiana State AGas victim2024-08-28
Phase II Systems dba PARS reported a data breach to the Indiana Attorney General. 9 Indiana residents were affected. 1,170 individuals affected in total.
- California State AGas victim2021-12-31
Phase II Systems (d/b/a PARS) experienced a phishing incident where an unauthorized party accessed an employee's email account between March 31, 2021, and May 24, 2021. The accessed account contained personal information, including full names and Social Security numbers. The company secured the account, engaged external cybersecurity professionals, and offered one year of credit monitoring to affected individuals.