HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
DJO, LLC
bd_07647e28074c559e · schema v1 · pii pii-v1
Full breach record for DJO, LLC →DJO Global, Inc. reported a data breach occurring November 8-9, 2020, discovered November 16, 2020. Cyber criminals exfiltrated personal information including names, SSNs, driver's license numbers, health insurance info, and financial account data. DJO engaged a cybersecurity firm, strengthened security measures, and offered 24 months of credit monitoring via TransUnion. No evidence of misuse was found at the time of notification.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_352070e577aafa27Montana State AGfiled 2020-12-23Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197509
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2020
- Raw hash
- b82c24db982c1e237964565bb939b1ed801ec9ce5714ed480e8f76ce5144ef7f
Reporting entity
- Name
- DJO, LLCnorm: djo
- Domain
- djoglobal.com
Victim entity
- Name
- DJO, LLCnorm: djo
- Domain
- djoglobal.com
Incident
- Discovered
- Nov 16, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.