HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
THE TRAVELERS INDEMNITY COMPANY
bd_0e32296c121ab0b7 · schema v1 · pii pii-v1
Full breach record for THE TRAVELERS INDEMNITY COMPANY →The Travelers Indemnity Company reported a data breach involving its agency portal. Between April 7, 2021, and November 17, 2021, an unauthorized party used stolen credentials of a limited number of agents to access customer information sourced from a third party. The incident was discovered on November 12, 2021. Affected data included names and addresses. Travelers reset accounts, engaged law enforcement, and offered 12 months of credit monitoring and dark web monitoring via Identity Force.
California clockDiscovered Nov 12, 2021 → Notified Dec 10, 202128d ✓ CA 60-day OK28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_535faad79ce2f641Oregon State AGfiled 2021-12-10Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548420
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 10, 2021
- Raw hash
- 14a1110beca9f332e4aa7693ae81820b1cccd113bcf5d7d25abc07e77ed8d469
Reporting entity
- Name
- THE TRAVELERS INDEMNITY COMPANYnorm: the travelers indemnity
Victim entity
- Name
- THE TRAVELERS INDEMNITY COMPANYnorm: the travelers indemnity
Incident
- Discovered
- Nov 12, 2021
- Materiality determined
- —
- Notification sent
- Dec 10, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reporting the event to federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 28d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 12, 2021→ Notified: Dec 10, 202128d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.