Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTHigh
Wellfleet Insurance Company
bd_15aee2a821b4e1ff · schema v1 · pii pii-v1
Full breach record for Wellfleet Insurance Company →Wellfleet Insurance Company reported a data breach affecting 2,949 individuals due to a phishing attack that compromised two email accounts. The incident occurred on multiple dates in 2020 (August 6, August 24, and October 2), and was discovered when a third-party service provider confirmed the breach on May 3, 2021, and reported it to Wellfleet on June 23, 2021. The compromised information included names and Social Security numbers. Affected individuals were notified around July 30, 2021, and offered identity theft protection services.
Maine clockDiscovered Jun 23, 2021 → Filed with AG Jul 7, 202114d ✓ ME AG ≤30d14 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_cde7be5a45d6e1d2Montana State AGfiled 2021-07-08(1d gap)Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/2948fe94-8408-43d9-b142-50512abad8a7.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2021
- Raw hash
- 14ff19cc75990a9d486ac3c28b14a21e3c77ca7c2d4672457d14b5f6c75a9287
Reporting entity
- Name
- Wellfleet Insurance Companynorm: wellfleet insurance
Victim entity
- Name
- Wellfleet Insurance Companynorm: wellfleet insurance
Incident
- Discovered
- Jun 23, 2021
- Materiality determined
- —
- Notification sent
- Jul 30, 2021
- Affected individuals
- 2,949
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 14d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 23, 2021→ Filed with AG: Jul 7, 202114d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.