Social EngineeringPhishingCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICLowContained
EyeMed Vision Benefits
bd_03f6bce6b4d9bc45 · schema v1 · pii pii-v1
Full breach record for EyeMed Vision Benefits →EyeMed Vision Care LLC notified South Carolina residents of a data breach occurring between June 24 and July 1, 2020. An unauthorized individual accessed an EyeMed email mailbox and sent phishing emails to contacts in the address book. EyeMed secured the mailbox, engaged a cybersecurity firm, reset passwords, and provided two years of free identity monitoring via Kroll. Personal information of vision benefit recipients may have been accessed.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_34d1a19c2cb74c79California State AGfiled 2020-12-11(47d gap)Verified
- bd_dd7329e4945257eeDelaware State AGfiled 2020-12-11(47d gap)Verified
- bd_cf86ae44e1360d1cMaine State AGfiled 2020-11-30(58d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2020/EyeMed.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2021
- Raw hash
- 2d15c1e62ed56d2bf7e2cd197d514d47d4e36394318664831413cbad50bcfa64
Reporting entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Victim entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Incident
- Discovered
- Jul 1, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 30 weeks(210 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.