Social EngineeringPhishingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
flexPATH Strategies
bd_0691b0e3d1dc7a91 · schema v1 · pii pii-v1
Full breach record for flexPATH Strategies →flexPATH Strategies, LLC, a retirement plan advisory firm, reported a phishing incident on December 7, 2018, where an unauthorized actor accessed an employee's email account. The breach potentially exposed client employee personal information (PII). flexPATH secured the account, engaged forensic investigators, and offered one year of complimentary credit monitoring via Experian IdentityWorks.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0172292eef70ab30Hawaii State AGfiled 2019-03-15(33d gap)Verified
- bd_5c77e09d3d33f3b8Montana State AGfiled 2019-03-15(33d gap)Candidate
- bd_7a883bef71700ef0Washington State AGfiled 2019-03-15(33d gap)Verified
- bd_956af0e49a3ab8c0California State AGfiled 2019-03-15(33d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 33d gap
- bd_be14e8f992f427b8Oregon State AGfiled 2019-03-15(33d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-146426
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2019
- Raw hash
- 9ab4365419fce7a34f83b1498ccd5028640a7cb9b79de5f1be5b1bd9d88c95f1
Reporting entity
- Name
- flexPATH Strategiesnorm: flexpath strategies
Victim entity
- Name
- flexPATH Strategiesnorm: flexpath strategies
Incident
- Discovered
- Dec 14, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 weeks(124 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.