HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTPIIMediumContained
MAPFRE ASSURANCE
bd_1a1a816e67851252 · schema v1 · pii pii-v1
Full breach record for MAPFRE ASSURANCE →Between July 1 and July 2, 2023, an unknown party used previously possessed information to access additional data via MAPFRE's Massachusetts online quoting platform. The attacker obtained driver's license numbers and vehicle information (make, model, year, VIN). MAPFRE took down the platform, investigated, reported to law enforcement, and implemented additional controls. Affected individuals are offered 12 months of Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-573043
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 8, 2023
- Raw hash
- d87811c909d2bb56e3e1e5456758fc09dfbbf940493ca41827633f939ccdadf9
Reporting entity
- Name
- MAPFRE ASSURANCEnorm: mapfre assurance
Victim entity
- Name
- MAPFRE ASSURANCEnorm: mapfre assurance
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Sep 8, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.