MalwareRansomwareSupply Chain (3P Vendor)Customer Data InvolvedData EncryptedPHIIDENTITY_BASICLowContained
Compton Eyecare Optometry, Inc.
bd_1813cb18f424be53 · schema v1 · pii pii-v1
Full breach record for Compton Eyecare Optometry, Inc. →Compton Eye Care Optometry notified the California AG of a ransomware attack on its cloud provider, DataHEALTH, Inc., on November 3, 2021. The attacker accessed data via a third-party software vulnerability. Personal information, including names and potentially PHI, was compromised. DataHEALTH contained the incident, engaged forensics, notified the FBI, and offered one year of identity monitoring via Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551300
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 28, 2022
- Raw hash
- 42d1afcb51499c94a2d5dc4ac8bf7c9fc3223bdf6ed3964be69dc6f6f8839b59
Reporting entity
- Name
- Compton Eyecare Optometry, Inc.norm: compton eyecare optometry
- Domain
- comptoneyecare.com
Victim entity
- Name
- Compton Eyecare Optometry, Inc.norm: compton eyecare optometry
- Domain
- comptoneyecare.com
Incident
- Discovered
- Nov 3, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported to the FBI
- Third party
- via DataHEALTH, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 weeks(117 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.