Capital Formation Group, Inc.

Capital Formation Group, Inc.

The Maine Office of the Attorney General disclosed a data breach at Capital Formation Group, Inc., occurring between September 19, 2023, and October 25, 2023, due to unauthorized access to employee email accounts. The incident compromised sensitive data of 274 individuals, including 8 Maine residents. The exposed information included financial account numbers and related security details, posing a significant risk of identity theft and financial fraud. In response, the company is providing 24 months of identity theft protection services via IDX to affected individuals. The breach highlights vulnerabilities in email security protocols, potentially enabling attackers to exploit financial credentials for malicious purposes. While the exact method of intrusion remains undisclosed, the focus on employee accounts suggests a targeted phishing or credential-theft campaign.

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/0c809685-753b-4b65-8c6c-c17e9e4598a5.shtml

TPRM report: https://www.rankiteo.com/company/capital-formation-group-inc

"id": "cap547091725",
"linkid": "capital-formation-group-inc",
"type": "Breach",
"date": "9/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 274,
                        'name': 'Capital Formation Group, Inc.',
                        'type': 'Corporation'}],
 'attack_vector': 'Compromised Employee Email Accounts',
 'customer_advisories': '24-Month Identity Theft Protection Offered via IDX',
 'data_breach': {'data_exfiltration': 'Likely (Unauthorized Access to Emails)',
                 'number_of_records_exposed': 274,
                 'personally_identifiable_information': 'Yes (Linked to '
                                                        'Financial Data)',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Financial Account Numbers',
                                              'Security Details']},
 'date_detected': '2023-10-25',
 'date_publicly_disclosed': '2024-01-09',
 'description': 'The Maine Office of the Attorney General reported a data '
                'breach involving Capital Formation Group, Inc. on January 9, '
                '2024. The breach occurred from September 19, 2023, to October '
                '25, 2023, due to unauthorized access to employee email '
                'accounts, affecting 274 individuals, including 8 residents of '
                'Maine. Compromised information included financial account '
                'numbers and related security details. The organization is '
                'offering 24 months of identity theft protection services '
                'through IDX.',
 'impact': {'brand_reputation_impact': 'Potential (Identity Theft Protection '
                                       'Offered)',
            'data_compromised': ['Financial Account Numbers',
                                 'Security Details'],
            'identity_theft_risk': 'High (24-Month Protection Offered)',
            'payment_information_risk': 'Yes (Financial Account Numbers '
                                        'Compromised)',
            'systems_affected': ['Employee Email Accounts']},
 'initial_access_broker': {'entry_point': 'Employee Email Accounts'},
 'references': [{'date_accessed': '2024-01-09',
                 'source': 'Maine Office of the Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
                                                       'Attorney General'},
 'response': {'communication_strategy': 'Public Disclosure via Maine Attorney '
                                        'General',
              'recovery_measures': '24-Month Identity Theft Protection for '
                                   'Affected Individuals',
              'third_party_assistance': 'IDX (Identity Theft Protection '
                                        'Services)'},
 'title': 'Capital Formation Group, Inc. Data Breach via Unauthorized Email '
          'Access',
 'type': 'Data Breach (Unauthorized Access)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.