Foster LLP, a law firm, notified the New Hampshire Attorney General of a data security incident involving unauthorized access to a corporate email account. An unauthorized user accessed the account for two days (Feb 3-5, 2021) likely via phishing. The breach potentially exposed names, SSNs, driver's licenses, passport numbers, financial/credit card info, and biometric data of 2 New Hampshire residents. Foster changed passwords, implemented security controls, and provided 12 months of credit monitoring via IDX.
Affected (this filing): 2