MalwareRansomwareRansom DemandedRansom PaidData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTEMPLOYMENTMediumResolved
BBS Financial Services, LLC
bd_055878f91c03cfc4 · schema v1 · pii pii-v1
Full breach record for BBS Financial Services, LLC →BBS Financial Services, LLC experienced a ransomware incident where a sophisticated threat actor exfiltrated data from its network. The breach occurred on December 19, 2023, and was discovered on January 29, 2024. Affected data included medical billing records, tax records, and payroll information containing PII, PHI, SSNs, and financial account numbers. BBS paid a ransom to the attacker, who subsequently destroyed the data. The company notified the FBI and IRS, activated IRS fraud detection systems, and offered two years of credit monitoring to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_19b6ae23508a8036Maine State AGBianLianfiled 2024-11-11Candidate
- bd_1da1372591c52265Montana State AGfiled 2024-11-11Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-594712
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 11, 2024
- Raw hash
- 9108a9ac14496b659b4152bfc23c75a0b9afaafb9e946538d76b78fe8a3f5f0f
Reporting entity
- Name
- BBS Financial Services, LLCnorm: bbs financial
- Domain
- bbs1040.com
Victim entity
- Name
- BBS Financial Services, LLCnorm: bbs financial
- Domain
- bbs1040.com
Incident
- Discovered
- Jan 29, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed a report with the FBIContacted the cybersecurity division of the Internal Revenue Service (IRS)
Compliance
- Time to disclose
- 41 weeks(287 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.