HackingSQL InjectionData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCriticalContained
Catholic United Financial
bd_095ea08906d84f19 · schema v1 · pii pii-v1
Full breach record for Catholic United Financial →Catholic United Financial experienced a data breach involving SQL injection attacks on its web server, potentially exposing personal information of approximately 127,310 members, including Social Security numbers. The incident occurred starting November 12, 2016, and was discovered on September 6, 2017. The company shut down its website, engaged forensic investigators, and notified law enforcement. Affected individuals were offered two years of identity monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_163b0a2490838b83Montana State AGfiled 2017-10-06Candidate
- bd_8e14bc0185707723Washington State AGfiled 2017-10-06Verified by operator
- bd_a56592d36390de29Oregon State AGfiled 2017-10-13(7d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-102483
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2017
- Raw hash
- b2d412aef60425e2136ee98a28932182962cebc1a12967561f23ddd08ad5352c
Reporting entity
- Name
- Catholic United Financialnorm: catholic united financial
Victim entity
- Name
- Catholic United Financialnorm: catholic united financial
Incident
- Discovered
- Sep 6, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 127,310
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Ramsey County, Minnesota sheriffNotified the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.