Between March 26, 2018, and April 6, 2018, inbound emails sent to an employee of the Organization were forwarded to unknown email addresses. The Organization discovered the incident on April 6, 2018, when the employee noticed she was not receiving emails on her desktop or Office 365 account. The Organization investigated, and found malware on the computer’s Google Chrome browser, which was removed by an external IT company on April 10, 2018. The cause of the incident is not known, but is suspected to be the staff member clicking either on a phishing email with a malicious link or attachment, or on a malicious link within a Google Chrome browser window.

