Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
TRUEbenefits LLC
bd_15431eb24bf8881d · schema v1 · pii pii-v1
Full breach record for TRUEbenefits LLC →TRUEbenefits LLC, an insurance brokerage, reported a security incident on May 19, 2017, involving unauthorized access to an employee's email account via a phishing scheme. The breach exposed names, Social Security numbers, and health plan details (diagnoses, claims, invoices) of clients and their dependents. TRUEbenefits secured the account, engaged forensic investigators, and offered two years of Experian IdentityWorks monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_01042eb2a1c1134fOregon State AGfiled 2017-09-18Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101975
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 18, 2017
- Raw hash
- 90c12618659e7f4ba8bc7e545975ed7359ccf9f5f8bc919907acf20118922d08
Reporting entity
- Name
- TRUEbenefits LLCnorm: truebenefits
Victim entity
- Name
- TRUEbenefits LLCnorm: truebenefits
Incident
- Discovered
- Jun 26, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.