Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICHEALTH_BASICPHILowContained
Outcomes
bd_1534c283b261f9d6 · schema v1 · pii pii-v1
Full breach record for Outcomes →Outcomes One, Inc. experienced a phishing incident on July 1, 2025, resulting in unauthorized access to an employee's email account. The attacker accessed files and emails containing demographic and health insurance information for some individuals. Social Security numbers were not involved. Outcomes secured the account, engaged third-party investigators, and implemented enhanced security safeguards and employee training.
California clockDiscovered Jul 1, 2025 → Notified Sep 10, 202571d ✗ CA 60-day late16 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_a6f792d784d84ba3Texas State AGfiled 2025-10-24(1d gap)Verified
- bd_25a352c6de9ebeffWashington State AGfiled 2025-09-23(30d gap)Verified
- bd_30e22ddaec24070eCalifornia State AGfiled 2025-09-23(30d gap)Verified
- bd_a6e85691ffe67aceOregon State AGfiled 2025-09-23(30d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 30d gap
- bd_bfd803f20d5ab6cdHHS OCRfiled 2025-09-23(30d gap)Verified
- bd_d5b332c2531136fbMontana State AGfiled 2025-09-23(30d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-613263
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 23, 2025
- Raw hash
- 6081495625757248f66a5c58877b0a8450ab3e5d029f7787622de361a98de332
Reporting entity
- Name
- Outcomesnorm: outcomes
- Domain
- outcomes.com
Victim entity
- Name
- Outcomesnorm: outcomes
- Domain
- outcomes.com
Incident
- Discovered
- Jul 1, 2025
- Materiality determined
- —
- Notification sent
- Sep 10, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- CA 60-day late · 71d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 1, 2025→ Notified: Sep 10, 202571d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.