MalwareRansomwarePhishingData EncryptedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
SUNMED GROUP HOLDINGS, LLC
bd_090a534a2bad3b77 · schema v1 · pii pii-v1
Full breach record for SUNMED GROUP HOLDINGS, LLC →SunMed Group Holdings, LLC experienced a ransomware incident on October 11, 2020, likely initiated via a phishing email link clicked by an employee. The attack encrypted server files. The company contained the threat, restored operations, and engaged external cybersecurity professionals and law enforcement. On February 21, 2021, the company determined that personal information, including Social Security numbers, may have been acquired by the threat actor. Affected individuals were offered one year of complimentary credit monitoring.
California clockDiscovered Oct 11, 2020 → Notified Feb 21, 2021133d ✗ CA 60-day late23 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539296
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2021
- Raw hash
- d7f1d23a24b1616797d7c9e153df8eaf322831418e66cb2acc0fa283e3f73ad9
Reporting entity
- Name
- SUNMED GROUP HOLDINGS, LLCnorm: sunmed group
Victim entity
- Name
- SUNMED GROUP HOLDINGS, LLCnorm: sunmed group
Incident
- Discovered
- Oct 11, 2020
- Materiality determined
- —
- Notification sent
- Feb 21, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(159 days from discovery to filing)
- Compliance flags
- CA 60-day late · 133d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 11, 2020→ Notified: Feb 21, 2021133d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.