MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_GOVERNMENTPIIMediumContained
Morley
bd_2116a0563276834a · schema v1 · pii pii-v1
Full breach record for Morley →Morley Companies Inc. notified individuals of a ransomware incident starting August 1, 2021, which resulted in unauthorized access to files containing Social Security numbers. The company engaged forensic specialists, restored systems, and provided 24 months of credit and identity monitoring via IDX to affected individuals. Notification was sent February 1, 2022.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1f725c594085ad56Montana State AGfiled 2022-01-26(1d gap)Candidate
- bd_dc3604c81ee0700eNew Hampshire State AGfiled 2022-01-26(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2022/MorleyCompaniesInc.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2022
- Raw hash
- 07812fd70e40b65ebd56eac88501a4ef8453dd3e9b81e2c79e9badb3a666c3b1
Reporting entity
- Name
- Morleynorm: morley
- Domain
- shopmorley.com
Victim entity
- Name
- Morleynorm: morley
- Domain
- shopmorley.com
Incident
- Discovered
- Aug 1, 2021
- Materiality determined
- —
- Notification sent
- Feb 1, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 26 weeks(179 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.