HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Strategic Benefits Advisors, Inc.
bd_18a8bd76f672839b · schema v1 · pii pii-v1
Full breach record for Strategic Benefits Advisors, Inc. →Strategic Benefits Advisors, Inc. (SBA) disclosed a criminal cyberattack on September 19, 2021, affecting a limited number of individuals. The breach involved unauthorized access to files containing names, Social Security numbers, addresses, and dates of birth. SBA secured systems, engaged law enforcement, and provided 24 months of credit monitoring via Experian. The incident was discovered shortly after the breach occurred.
California clockDiscovered Sep 19, 2021 → Notified Nov 5, 202147d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_eea9a1cc29958d4eSouth Carolina State AGfiled 2021-11-08(3d gap)Verified
- bd_757fc0172a308c29Montana State AGfiled 2021-11-12(7d gap)Verified
- bd_ec306f1e59a5016eMaine State AGfiled 2021-11-12(7d gap)Verified
- bd_ee70dc26578ff3cbMaine State AGfiled 2021-10-28(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547258
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2021
- Raw hash
- c31ac4a3433ed591dd6967f483c96ba4fe9e677bb41a0eafae0377d4b527902f
Reporting entity
- Name
- Strategic Benefits Advisors, Inc.norm: strategic benefits advisors
Victim entity
- Name
- Strategic Benefits Advisors, Inc.norm: strategic benefits advisors
Incident
- Discovered
- Sep 19, 2021
- Materiality determined
- —
- Notification sent
- Nov 5, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 47d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 19, 2021→ Notified: Nov 5, 202147d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.