Catholic United Financial
bd_095ea08906d84f19 · schema v1 · pii pii-v1
Full breach record for Catholic United Financial →Catholic United Financial experienced an SQL injection attack on its web server, potentially exposing personal information including Social Security numbers for approximately 127,310 members. The intrusion occurred on November 12, 2016, but was not discovered until September 6, 2017. The organization shut down its website, engaged forensic investigators, and notified law enforcement. Affected individuals were offered two years of identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 12, 2016
Begins
Sep 6, 2017
Discovered
Oct 6, 2017
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_163b0a2490838b832017-10-06Candidate
- Washington State AGbd_8e14bc01857077232017-10-06Verified by operator
- New Hampshire State AGbd_444411c792158acf2017-10-05 · +1dVerified
- Massachusetts State AGbd_d98cc38a86f2cabd2017-10-12 · +6dVerified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- Oregon State AGbd_a56592d36390de292017-10-13 · +7dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Oct 5 (NH), last Oct 13 (OR) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.