After 24 days of updating my scratch list of incidents involving phishing for W-2 information (business email compromise), I decided to take stock and try to organize what we have so far. I was surprised to see that there were already 90 incidents (make that 126 as of May 18th). Most of these entries were found via media reports and reports to state attorneys general. Some were found via KrebsOnSecurity. In a few cases, it’s not totally clear whether an incident was a phishing attack or some other type of breach that compromised employee information.
Updated Mar 3, 2017: Because some additional reports from 2016 have become available, I have decided to update this post so that we have a better comparison for the 2017 list. This will likely not be the final update for this list, as the state has yet to finish uploading all its 2016 data.
If you have any additions, deletions, or corrections to suggest, please email me at breaches [at] databreaches.net.
- A& A Ready Mixed Concrete
- Academy of Art Institute
- Acronis
- Actifio Inc.
- Advance Auto Parts
- Agenus
- Alpha Payroll Services
- American Type Culture Collection
- AmeriPride Services Inc.
- Anthelio Healthcare Solutions Inc.
- Applied Systems Inc.
- ARC International
- Areas
- ARIAD Pharmaceuticals
- Ash Brokerage Corp (423)
- Aspect
- ASPIRAnet
- Asure Software
- Astreya Partners, Inc.
- Avendra
- Avention
- Avinger, Inc.
- AxoGen, Inc.
- BackOffice Associates
- Behavioral Science Technology
- Ben Bridge Jeweler, Inc.
- Billy Casper Golf
- BloomReach
- Boltech Mannings
- BrightView
- Bristol Farms
- Brunswick Corporation ( Brunswick Boat Group, Boston Whaler, Cybex International, Leiserv Inc, Sea Ray Boats, Inc)
- Brunswick School District
- Care.com (and its subsidiaries)
- CareCentrix
- Central Concrete Supply Co. (Right Away Redy Mix, Rock Transport, Inc.)
- Century Fence
- Champlain Oil
- City of Hope
- City of Plainfield, NJ
- Clay County Medical Center (?)
- Client Network Services
- Clinton Health Access Initiative
- Concord School District (NH)
- ConvaTec Inc.
- Convey Health Solutions
- Conway Group
- Crane Co.
- Dare Enterprises (via Blue Belt Technologies)
- DataXu Inc.
- DealerSocket Inc.
- Dennis Group
- Digilant
- Dixie Group
- Dynamic Aviation
- eClinicalWorks
- EMSI
- Endologix Inc.
- EPTAM Plastics
- Equian, LLC (not discovered until March, 2017)
- Essex, VT
- Evening Post Industries
- EWTN Global Catholic Network
- Fast Company
- Foss Manufacturing Company
- Gamesa Wind US
- General Communication, Inc. (GCI, Denali Media, UUI and Unicom)
- Girl Scouts of Connecticut (372)
- Girl Scouts of Gulf Coast Florida
- GoldKey|PHR
- Gryphon Technologies
- HAECO
- Highway Toll Administration
- Hudson City School District
- Hutchison Community College
- I.M. Systems Group
- IASIS
- Information Innovators Inc.
- Information Resources
- InvenSense
- InVentive Health, Inc.
- ISCO Industries
- J. Polep Distribution Services
- Kalamazoo College (1,600)
- Kantar Group (4,266)
- Kentucky State University (1,071)
- Kids Dental Kare
- Krispy Kreme
- Lamps Plus and Pacific Coast Lighting
- Land Title Guarantee Company
- Lanyon Solutions
- Lawrence Public Schools
- LAZ Parking
- Magnolia Health Corporation
- Main Line Health
- Management Health Systems d/b/a MedPro Heathcare Staffing
- Mansueto Ventures (on behalf of Inc.)
- Maritz Holdings, Inc.
- Masy Bioservices
- Matric NAC and Matrix Service Company
- MCM Staffing
- Medieval Times
- Meeting Street School
- Mercy Housing
- Michels (1,911)
- Millenium Engineering and Integration
- Mitchell International Inc.
- Milwaukee Bucks
- MNP on behalf of its affiliate, General Fasteners Company
- Momentum for Mental Health
- Monarch Beverage Company
- Moneytree
- Morongo Casino
- MYR Group
- Nation’s Lending Corporation
- NetBrain
- Netcracker Technology
- New Leaders
- Nexion Healthcare Management, Inc.
- NTT Data
- O.C. Tanner
- Olympia School District
- OpSec Security
- PerkinElmer
- Pharm-Olam International
- PhysMed Management
- Pivotal Software, Inc.
- Polycom
- Primary Residential Mortgage, Inc. (PRMI)
- Proskauer Rose
- Puppet, Inc.
- Pure Integration, LLC
- QTI Group
- RagingWire Data
- Relief International
- Rhode Island Blood Center
- Rightside
- Robert Rauschenberg Foundation
- Rockhurst University
- RugDoctor
- Ryman Hospitality Properties (Grand Ole Opry, WSM-AM, Wildhorse Saloon, four large resort hotels, two smaller hotels, a golf course, and Nashville’s General Jackson Showboat).
- Saint Agnes Medical Center (2,800)
- Saint Joseph’s Healthcare System
- SalientCRGT
- Santa Rosa Consulting
- School Administrative District 4 (Maine)
- Seagate Technology
- Sequoia Union High School District
- Seven Hills Foundation
- SevOne
- Silicon Laboratories
- Single Digits
- Snapchat
- Solano Community College
- Spectrum, Inc.
- Springfield City Utilities
- Sprouts (21,000)
- Symphony EYC
- Symphony Health Solutions Corp.
- The Home for Little Wanderers
- Tidewater Community College (3,193)
- Tom McLeod Software Corps
- Total Community Options Inc. DBA InnovAge
- Tricerat, Inc.
- Turner Construction
- Umstead Hotel & Spa
- ValMark Securities
- VBrick Systems
- Verity Health System
- Veterans Management Services
- Washington Elementary School District
- Whiting-Turner Contracting Company (1,987)
- WorkCare
- Wynden Stark, dba GQR Global Markets/City Internships
- York Hospital
- YourEncore
Any chance you can add the states? I see my school district up there but I don’t know if it’s the same state.
If you search my site for the name of the school district, you should find my coverage on the incident which should give you the state.
Duh. Thanks! Different state, NC.
Great work! Thank you.
This is an impressive list great work on compiling! Phishing is a serious risk and one that is best mitigated by end user awareness combined with a good email gateway solution. [advertising material deleted by moderator – not allowed on this site, thanks.]