Boulos Asset Management

Boulos Asset Management

On March 30, 2021, Boulos Asset Management experienced a data breach due to an external system hacking incident, as reported by the Maine Office of the Attorney General on June 7, 2021. The breach exposed sensitive personal and financial information of 692 individuals, including 629 Maine residents. Compromised data included full names, mailing addresses, Social Security numbers (SSNs), and limited bank account details. The incident highlights a significant security failure, as the exposed data particularly SSNs and bank information poses severe risks of identity theft, financial fraud, and long-term reputational harm to affected individuals. The breach’s scope suggests targeted exploitation of vulnerabilities, likely for malicious financial gain or data monetization. While the exact method of the hack remains undisclosed, the impact extends beyond immediate financial losses, potentially affecting victims’ creditworthiness and trust in the company’s data protection measures. The breach underscores the critical need for robust cybersecurity frameworks, especially in sectors handling highly sensitive personal and financial records. The delayed public disclosure (over two months after the incident) may further exacerbate regulatory and legal repercussions for the firm.

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/0cf8578f-0b3b-4ba0-bae9-45289d1a7ff6.shtml

TPRM report: https://www.rankiteo.com/company/boulos-financial-group-inc-

"id": "bou941091725",
"linkid": "boulos-financial-group-inc-",
"type": "Breach",
"date": "3/2021",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 692,
                        'industry': 'Asset Management / Real Estate',
                        'location': 'Maine, USA',
                        'name': 'Boulos Asset Management',
                        'type': 'Company'}],
 'attack_vector': 'External System Breach (Hacking)',
 'data_breach': {'data_exfiltration': 'Likely (data accessed by unauthorized '
                                      'party)',
                 'number_of_records_exposed': 692,
                 'personally_identifiable_information': ['Full names',
                                                         'Mailing addresses',
                                                         'Social Security '
                                                         'numbers'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Financial Data']},
 'date_detected': '2021-03-30',
 'date_publicly_disclosed': '2021-06-07',
 'description': 'The Maine Office of the Attorney General reported a data '
                'breach involving Boulos Asset Management on June 7, 2021. The '
                'breach occurred on March 30, 2021, due to an external system '
                'breach (hacking), potentially affecting 692 individuals, '
                'including 629 residents. Compromised information included '
                'full names, mailing addresses, social security numbers, and '
                'limited bank account information.',
 'impact': {'data_compromised': ['Full names',
                                 'Mailing addresses',
                                 'Social Security numbers',
                                 'Limited bank account information'],
            'identity_theft_risk': 'High (SSNs and bank account info exposed)',
            'payment_information_risk': 'Limited (partial bank account info '
                                        'exposed)'},
 'post_incident_analysis': {'root_causes': 'External system breach (hacking)'},
 'references': [{'date_accessed': '2021-06-07',
                 'source': 'Maine Office of the Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
                                                       'Attorney General'},
 'response': {'communication_strategy': 'Public disclosure via Maine Attorney '
                                        'General'},
 'title': 'Boulos Asset Management Data Breach (2021)',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.