Social EngineeringPhishingTargetedPIIIDENTITY_BASICLowContained
EyeMed Vision Benefits
bd_1901228616916967 · schema v1 · pii pii-v1
Full breach record for EyeMed Vision Benefits →EyeMed Vision Care LLC reported a phishing incident where an unauthorized individual accessed an email mailbox from June 24 to July 1, 2020. The attacker sent phishing emails to contacts in the mailbox. Personal information of vision benefit recipients may have been accessed. EyeMed secured the account, engaged forensic investigators, reset passwords, and provided two years of identity monitoring services.
California clockDiscovered Jul 1, 2020 → Notified Aug 14, 202044d ✓ CA 60-day OK13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_62dc6484cbe942d7Montana State AGfiled 2020-09-28Candidate
- bd_873b63c5791a9fb8Maine State AGfiled 2020-09-28Verified
- bd_51ab8a9387df3353Oregon State AGfiled 2020-10-12(14d gap)Verified
- bd_5b0c8c38829e67fcWashington State AGfiled 2020-10-12(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194542
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 28, 2020
- Raw hash
- afd5b853ed02087d9dda3da0e2dd34490b49b73415a85877c51dd0ecf666f3d4
Reporting entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Victim entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Incident
- Discovered
- Jul 1, 2020
- Materiality determined
- —
- Notification sent
- Aug 14, 2020
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 weeks(89 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 44d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 1, 2020→ Notified: Aug 14, 202044d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.