MalwareProfessional ServicesHealthcareProfessional ServicesRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Morley Companies, Incorporated
bd_15c18691b2f9b9ac · schema v1 · pii pii-v1
Full breach record for Morley Companies, Incorporated →Morley Companies, Inc., a Michigan-based health plan processing firm, experienced a ransomware-type malware attack beginning August 1, 2021, which prevented access to certain files and resulted in unauthorized access to personal information including Social Security numbers. The company discovered the incident, engaged third-party forensic specialists, and confirmed affected individuals in March 2022. IDX credit and identity monitoring services were offered for 24 months.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0231bc3362ac2b5aWashington State AGfiled 2022-03-21Verified by operator
- bd_847199de57393300Oregon State AGfiled 2022-02-08(41d gap)Verified by operator
- bd_1a3787d24bb59c4eCalifornia State AGfiled 2022-02-01(48d gap)Verified by operator
- bd_a6ad4289c8bc0ba5Maine State AGfiled 2022-02-01(48d gap)Verified by operator
Show 2 more filings ↓Show fewer ↑up to 54d gap
- bd_c62c3bad868a53b8HHS OCRfiled 2022-02-01(48d gap)Verified
- bd_7614ce10228ad93aMaine State AGfiled 2022-01-26(54d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551860
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2022
- Raw hash
- c3876b7e1752837e433e08669883b2ba44450a24740744c3414e66b0c848fe94
Reporting entity
- Name
- Morley Companies, Incorporatednorm: morley companies
Victim entity
- Name
- Morley Companies, Incorporatednorm: morley companies
- Domain
- morleycompanies.com
- Industry
- Professional ServicesllmHealthcarellm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 21, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.