DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedIdentity (basic)Government IDFinancial accountMediumContained

Ursus, Inc.

bd_16435c4852f6ec48 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 25, 2016

Filed

Sep 8, 2016

To disclose

19 weeks

Affected

42state residents only

Linked

4 filings

Confidence

66%
Full breach record for Ursus, Inc.

Ursus Holdings, LLC notified the NH AG of a phishing incident where an employee's credentials were stolen, leading to unauthorized access to email accounts. Documents containing PII (names, SSNs) and financial data of 42 NH residents were accessed. Ursus isolated accounts, reset passwords, implemented MFA, and planned to offer credit monitoring.

Incident timeline

undetected · 35 days
discovery → filing · 19 weeks / 136 days

Mar 21, 2016

Begins

Apr 25, 2016

Discovered

Sep 8, 2016

Filed

vs. sector median

+1 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
New Hampshire State AGSep 8 · first · this page

Pattern: first filing Sep 8 (NH), last Sep 19 (CA) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.