HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENTMediumContained
MultiPlan, Inc.
bd_0cda4366c590210b · schema v1 · pii pii-v1
Full breach record for MultiPlan, Inc. →Orrick, Herrington & Sutcliffe LLP experienced a security incident where an unauthorized third party gained remote access to its network between February 28 and March 13, 2023. The attacker obtained files containing personal information, including data related to MultiPlan, Inc. clients. Orrick detected the access on March 13, 2023, blocked it, and engaged forensic experts. Identity monitoring services are being offered to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578559
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 28, 2023
- Raw hash
- 73bfcc55c3b15b1c245002bf316f546be4038f7ee0af16c70d98eed839875529
Reporting entity
- Name
- Orrick, Herrington & Sutcliffe LLPnorm: orrick herrington sutcliffe
- Domain
- orrick.com
Victim entity
- Name
- MultiPlan, Inc.norm: multiplan
- Domain
- orrick.com
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Third party
- via Orrick, Herrington & Sutcliffe LLP
Compliance
- Time to disclose
- 41 weeks(290 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.