On March 24, 2020, the Organization?s general email account was used to send out phishing emails. The person that accessed the account had brief access to the inbox. The Organization and its email provider were not able to determine which emails the intruder may have opened in that time. The Organization reported the breach ?occurred during the COVID-19 pandemic during the Organization?s transition to working remotely as mandated by the Federal Government?. The breach was discovered the same day when the Organization noticed unusual activity with its general email account.

