DisclosureLens
AccidentalFinancial ServicesFinanceMisconfigurationCustomer Data InvolvedIdentity (basic)Government IDMediumResolved

Ascensus Group Holdings, Inc.

bd_1e7de0859d782bbe · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 23, 2016

Filed

Sep 19, 2016

To disclose

27 days

Affected

Not disclosed

Linked

2 filings

Confidence

64%
Full breach record for Ascensus Group Holdings, Inc.6 incidents on file

Ascensus, Inc., recordkeeper for the Menzies Aviation (USA), Inc. 401(k) Plan, notified the California Attorney General of a data breach. On August 23, 2016, Ascensus discovered a website configuration error that inadvertently allowed the plan administrator of another Ascensus retirement plan to access personal information of participants. The exposed data included names, addresses, birth dates, and Social Security numbers. The configuration error was immediately terminated upon discovery. Ascensus offered 12 months of complimentary identity protection through TrustedID to affected individuals.

California clockDiscovered Aug 23, 2016Notified Sep 21, 201629d CA 60-day OK27 days discovery → filing

Incident timeline

undetected · 116 days
discovery → filing · 27 days

Apr 29, 2016

Begins

Aug 23, 2016

Discovered

Sep 19, 2016

Filed

vs. sector median

5 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Washington State AGSep 19 · first
California State AGSep 19 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.