The Maine Office of the Attorney General reported a data breach involving The Richards Group on February 17, 2021. The breach occurred between May 1, 2020, and May 11, 2020, due to an email phishing attack that compromised an employee's email account, affecting a total of 25,179 individuals, including 48 Maine residents. Personal information involved included full names, Social Security numbers, dates of birth, and medical information.
TPRM report: https://www.rankiteo.com/company/therichardsgroup
"id": "the331072825",
"linkid": "therichardsgroup",
"type": "Breach",
"date": "5/2020",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 25179,
'name': 'The Richards Group',
'type': 'Company'}],
'attack_vector': 'Phishing',
'data_breach': {'number_of_records_exposed': 25179,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Full names',
'Social Security numbers',
'Dates of birth',
'Medical information']},
'date_detected': '2021-02-17',
'date_publicly_disclosed': '2021-02-17',
'description': 'The Maine Office of the Attorney General reported a data '
'breach involving The Richards Group on February 17, 2021. The '
'breach occurred between May 1, 2020, and May 11, 2020, due to '
"an email phishing attack that compromised an employee's email "
'account, affecting a total of 25,179 individuals, including '
'48 Maine residents. Personal information involved included '
'full names, Social Security numbers, dates of birth, and '
'medical information.',
'impact': {'data_compromised': ['Full names',
'Social Security numbers',
'Dates of birth',
'Medical information']},
'initial_access_broker': {'entry_point': 'Email Phishing'},
'post_incident_analysis': {'root_causes': 'Email phishing attack'},
'references': [{'date_accessed': '2021-02-17',
'source': 'Maine Office of the Attorney General'}],
'title': 'Data Breach at The Richards Group',
'type': 'Data Breach',
'vulnerability_exploited': 'Email Account Compromise'}