MalwareProfessional ServicesProfessional ServicesRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumResolved
Morley Companies, Incorporated
bd_1a3787d24bb59c4e · schema v1 · pii pii-v1
Full breach record for Morley Companies, Incorporated →Morley Companies, Inc., a Michigan-based firm processing information for health plans, experienced a ransomware attack beginning August 1, 2021. The malware prevented access to files and allowed unauthorized access to data containing personal information including Social Security numbers. On January 18, 2022, the company confirmed affected individuals. Notification letters were sent February 1, 2022. IDX credit/identity monitoring (24 months) was offered to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_a6ad4289c8bc0ba5Maine State AGfiled 2022-02-01Verified by operator
- bd_c62c3bad868a53b8HHS OCRfiled 2022-02-01Verified
- bd_7614ce10228ad93aMaine State AGfiled 2022-01-26(6d gap)Verified
- bd_847199de57393300Oregon State AGfiled 2022-02-08(7d gap)Verified by operator
Show 2 more filings ↓Show fewer ↑up to 48d gap
- bd_0231bc3362ac2b5aWashington State AGfiled 2022-03-21(48d gap)Verified by operator
- bd_15c18691b2f9b9acCalifornia State AGfiled 2022-03-21(48d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-550610
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2022
- Raw hash
- 2d0a86ca21dd4352eead5b5d6b9945f4b6e0d93094c8a0c77d55fdbfec22a1f5
Reporting entity
- Name
- Morley Companies, Incorporatednorm: morley companies
- Domain
- morleycompanies.com
Victim entity
- Name
- Morley Companies, Incorporatednorm: morley companies
- Domain
- morleycompanies.com
- Industry
- Professional Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Feb 1, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated CollectionT1074 Data Staged
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.