HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Emanate Health Foundation
bd_15f2b13805246ff4 · schema v1 · pii pii-v1
Full breach record for Emanate Health Foundation →Emanate Health reported a data breach involving third-party vendor PaperlessPay Corporation. An unauthorized individual accessed PaperlessPay's SQL server on February 18, 2020, potentially exposing employee personal information including names, addresses, Social Security numbers, and partial bank account details. PaperlessPay shut down servers and cooperated with DHS and FBI investigations. Emanate Health offered 12 months of free credit monitoring to affected employees.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-192529
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 29, 2020
- Raw hash
- 2cbe5919dd4dd355ab7c8e26e4bcd247fcf9ebdcb02a1ccae17e0e4c4d68b0d1
Reporting entity
- Name
- Emanate Health Foundationnorm: emanate health
Victim entity
- Name
- Emanate Health Foundationnorm: emanate health
Incident
- Discovered
- Feb 19, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Joint investigation conducted by DHS and FBI
- Third party
- via PaperlessPay Corporation
- Initial access
- supply_chain
Compliance
- Time to disclose
- 23 weeks(161 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.