Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowResolved
UMass Memorial Health Care Master Pension Trust
bd_0aefe14a3374d53a · schema v1 · pii pii-v1
Full breach record for UMass Memorial Health Care Master Pension Trust →UMass Memorial Health reported a phishing incident that occurred between June 24, 2020, and January 7, 2021. The breach was discovered on August 25, 2021. The incident compromised names and financial account numbers or credit/debit card numbers with their access codes. In response, the company offered one year of credit monitoring and identity theft protection services through Experian to the 3 affected Maine residents.
Maine clockDiscovered Aug 25, 2021 → Filed with AG Oct 15, 202151d ⏱ ME AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_162fcaf04c5a3538HHS OCRfiled 2021-10-15Verified
- bd_28661c8ab6fb77e5New Hampshire State AGfiled 2021-10-15Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/472311e2-fa16-4151-9a28-8b894b291514.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 15, 2021
- Raw hash
- d38a3a2e8e4f868498e4de8f818ead7d1a4f81d3500db843b711ac5682623be0
Reporting entity
- Name
- UMass Memorial Health Care Master Pension Trustnorm: umass memorial health care master pension
- Domain
- umassmemorial.org
Victim entity
- Name
- UMass Memorial Health Care Master Pension Trustnorm: umass memorial health care master pension
- Domain
- umassmemorial.org
Incident
- Discovered
- Aug 25, 2021
- Materiality determined
- —
- Notification sent
- Oct 15, 2021
- Affected individuals
- 3
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Phishing
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- ME AG >30d · 51d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 25, 2021→ Filed with AG: Oct 15, 202151d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.