DisclosureLens
Social EngineeringEnergy & UtilitiesUtilitiesPhishingEmployee Data InvolvedTargetedGovernment IDIdentity (basic)Financial accountEmploymentMediumResolved

SUNRUN INC.

bd_0f1387b75910b066 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 20, 2017

Filed

Feb 2, 2017

To disclose

13 days

Affected

Not disclosed

Linked

3 filings

Confidence

65%
Full breach record for SUNRUN INC.

On January 20, 2017, Sunrun Inc. experienced a targeted phishing scam where a scammer impersonated the CEO to request employee W-2s from the payroll department. The phishing email was not recognized as a scam, resulting in the external disclosure of 2016 W-2s for current and former employees. Affected data included names, addresses, Social Security numbers, salaries, and taxes withheld. Sunrun notified the FBI, IRS, and state taxing authorities and offered two years of free credit monitoring via Experian's ProtectMyID Alert. The company is reinforcing its information security training to prevent future incidents.

California clockDiscovered Jan 20, 2017Notified Jan 30, 201710d CA 60-day OK13 days discovery → filing

Incident timeline

discovery → filing · 13 days

Jan 20, 2017

Begins

Jan 20, 2017

Discovered

Feb 2, 2017

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
California State AGFeb 2 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.