MalwareRansomwareRansom DemandedRansom PaidData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Horizon Actuarial
bd_0b8a8d1e0b2eb75a · schema v1 · pii pii-v1
Full breach record for Horizon Actuarial →Horizon Actuarial Services, LLC experienced a ransomware incident on November 10-11, 2021, where unauthorized actors accessed two servers and exfiltrated personal data. The company negotiated with and paid the attackers, who agreed to delete the data. Affected individuals received notification letters in January 2022 offering 12 months of identity monitoring services from Kroll. The FBI was notified.
California clockDiscovered Nov 12, 2021 → Notified Jan 13, 202262d ✗ CA 60-day late28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a9ca9bbf0b626c3fHawaii State AGfiled 2022-05-24Verified
- bd_3343e2ff6ac46177California State AGfiled 2022-05-18(6d gap)Candidate
- bd_15610822e41f867eCalifornia State AGfiled 2022-05-10(14d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553697
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 24, 2022
- Raw hash
- a7b0fc13f9bf7fdb9d9c850a80215ee5b4b8ded874c1c3bf0fe95444a604cba6
Reporting entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
Victim entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
Incident
- Discovered
- Nov 12, 2021
- Materiality determined
- Jan 13, 2022
- Notification sent
- Jan 13, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- provided notice to the FBI
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 28 weeks(193 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 12, 2021→ Notified: Jan 13, 202262d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.