DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDFinancial accountPIIMediumContained

Aladdin Capital

bd_1f948f109b746e05 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 24, 2020

Filed

Sep 27, 2021

To disclose

44 weeks

Affected

3state residents only

Linked

5 filings

Confidence

67%
Full breach record for Aladdin Capital

Aladdin Capital notified Montana residents of a data breach discovered on November 24, 2020. Unauthorized access occurred via phishing leading to compromised employee email accounts. Data exposed included names, addresses, SSNs, driver's licenses, and financial info. The company reset passwords, implemented MFA, and provided 12 months of credit monitoring.

Incident timeline

discovery → filing · 44 weeks / 307 days

Nov 24, 2020

Discovered

Sep 27, 2021

Filed

vs. sector median

+35 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Indiana State AGSep 27 · first
Massachusetts State AGSep 27 · first
Maine State AGSep 27 · first
Montana State AGSep 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.