CSIDB logo
Incident

Mansueto Ventures

Incident posture

Attack window
Mar 2016
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-11 00:00

Linked entities

Victim
Mansueto Ventures
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity incident impacted the publisher of Inc. and Fast Company, exposing employee wage information and Social Security numbers. Attackers exploited the stolen data to file fraudulent federal and state tax returns, affecting a significant portion of staff. Employees expressed frustration over the breach's personal consequences and criticized the company's security measures, particularly noting that sensitive data was stored unencrypted. While customer and subscriber information remained unaffected, concerns arose regarding potential compromises of 401(k) accounts and credit cards. The organization confirmed the breach, notified law enforcement, and internal communications addressed employee notifications through its CFO.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Mansueto Ventures, publisher of Inc. and Fast Company magazines, experienced a significant data breach compromising employee wage information and Social Security numbers. The breach was disclosed on March 4, 2016, after hackers exploited the stolen data to file fraudulent federal and state tax returns in employees' names. Multiple staff members confirmed unauthorized tax filings using their Social Security numbers, with one employee describing active efforts to resolve fraudulent state-local filings. Employees expressed frustration at having to expend personal time and resources to address identity theft consequences. Several criticized the company's cybersecurity measures, particularly noting that sensitive employee data had been stored unencrypted—a point of irony given the publications' focus on business best practices.

The company's Chief Financial Officer, Mark Rosenberg, assumed responsibility for notifying affected employees about the breach. Concerns among staff extended beyond tax fraud to potential compromises of 401(k) retirement accounts and credit card information. An internal company estimate suggested fraudulent tax filings had occurred using 90% of compromised employee identities, though Mansueto Ventures did not publicly verify this claim. The organization, founded by billionaire Joe Mansueto, confirmed the breach to authorities and engaged law enforcement. Officials stated customer, client, and subscriber data remained unaffected by the intrusion. No technical details regarding the breach methodology, detection timeline, or containment procedures were disclosed in public statements.

Sources

Sources available to members: 1 source.

CSIDB