DisclosureLens
Social EngineeringConstructionConstructionPhishingStolen CredentialsMulti-Stage ChainEmployee Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

SEMA Construction, Inc.

bd_0c20a52bba9ca7c9 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 4, 2020

Filed

Dec 30, 2020

To disclose

21 weeks

Affected

1state residents only

Confidence

66%
Full breach record for SEMA Construction, Inc.

SEMA Construction, Inc. notified employees of a phishing campaign that compromised account credentials and potentially exposed personal information including SSNs, bank details, and driver's licenses. Forensic investigators confirmed the compromise in August 2020. Notices were sent to affected employees starting October 2020, with additional notifications in December 2020. The company provided 12 months of credit monitoring.

Incident timeline

discovery → filing · 21 weeks / 148 days

Aug 4, 2020

Discovered

Dec 30, 2020

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.