Horizon Actuarial
bd_0f74d080348e1e13 · schema v1 · pii pii-v1
Full breach record for Horizon Actuarial →Horizon Actuarial Services, LLC reported a cybersecurity incident occurring November 10-11, 2021, where unauthorized actors accessed computer servers. The group claimed to have stolen personal data and demanded ransom. Horizon Actuarial paid the ransom in exchange for an agreement to delete and not distribute the information. The incident involved identity information (names, SSNs, DOBs) of benefit plan participants. Horizon Actuarial notified the FBI, engaged third-party specialists, and provided 12 months of complimentary identity monitoring services via Kroll to affected individuals. Notification to the Fund began January 13, 2022.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_60c050db559ca233New Hampshire State AGfiled 2022-03-24(18d gap)Candidate
- bd_57e4879b692c8a62New Hampshire State AGfiled 2022-03-22(20d gap)Candidate
- bd_acc2dcb63f662ce2New Hampshire State AGfiled 2022-03-22(20d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/05/Horizon-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2022
- Raw hash
- 00e8c74b282255af79578ced1feed10454dade5c9973f10c854b62fde332103a
Reporting entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
Victim entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
Incident
- Discovered
- Nov 12, 2021
- Materiality determined
- —
- Notification sent
- Jan 13, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- provided notice to the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(150 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.