HackingConstructionStolen CredentialsCapture App DataEmployee Data InvolvedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPIIPHIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSAUTHENTICATIONCREDENTIALSMediumContained
KPRS Construction Services
bd_05f3338a0ba7ca67 · schema v1 · pii pii-v1
Full breach record for KPRS Construction Services →KPRS Construction Services, Inc. experienced unauthorized access to employee email accounts during March–April 2019. The company learned of suspicious activity in late March 2019 and confirmed the compromise around June 14, 2019. Affected data included names, SSNs, driver's license numbers, health insurance/medical information, and for some individuals, payment card/bank account details and electronic account credentials. Notification letters were sent November 20, 2019.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-184651
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 25, 2019
- Raw hash
- ecc8b8f80df603add7026964f188c3a9aceb7cef96f5d57063e1f271b185aeeb
Reporting entity
- Name
- KPRS Construction Servicesnorm: kprs construction
- Domain
- kprsinc.com
Victim entity
- Name
- KPRS Construction Servicesnorm: kprs construction
- Domain
- kprsinc.com
- Industry
- Constructionllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 20, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPIIPHIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSAUTHENTICATIONCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.