HackingStolen CredentialsSupply Chain (3P Vendor)TargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
WASHINGTON NATIONAL INSURANCE COMPANY
bd_1088d79c4a9bd4e4 · schema v1 · pii pii-v1
Full breach record for WASHINGTON NATIONAL INSURANCE COMPANY →Washington National Insurance Company disclosed that a sophisticated threat actor targeted a senior officer's cellular account via a SIM swapping attack facilitated by a wireless carrier retailer. The actor bypassed multi-factor authentication to access company data, including policyholders' names, SSNs, and dates of birth. The incident was discovered on November 29, 2023. The company engaged law enforcement and forensic investigators, contained the access, and is offering identity theft protection.
California clockDiscovered Nov 29, 2023 → Notified Jan 26, 202458d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_11120bc7f0efd63aMaine State AGfiled 2024-01-30(1d gap)Candidate
- bd_1062194d9f8fbff4Montana State AGfiled 2024-01-31(2d gap)Verified
- bd_90bf9c26fb0cf0e4New Hampshire State AGScattered Spiderfiled 2024-01-31(2d gap)Verified
- bd_dd14b3bb28be9b92Indiana State AGfiled 2024-01-26(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580118
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2024
- Raw hash
- 471d6a76c3ec88062ac442c77981f642a9616277d6f007630f4a849cae04e9ea
Reporting entity
- Name
- WASHINGTON NATIONAL INSURANCE COMPANYnorm: washington national insurance
Victim entity
- Name
- WASHINGTON NATIONAL INSURANCE COMPANYnorm: washington national insurance
Incident
- Discovered
- Nov 29, 2023
- Materiality determined
- —
- Notification sent
- Jan 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcementWorking with the Federal Bureau of InvestigationWorking with the Offices of the United States Attorneys
- Third party
- via Wireless carrier retailer
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 58d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 29, 2023→ Notified: Jan 26, 202458d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.