Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICPIILowContained
WORLDWIDE INSURANCE SERVICES, LLC
bd_214cedcc74ff9823 · schema v1 · pii pii-v1
Full breach record for WORLDWIDE INSURANCE SERVICES, LLC →Worldwide Services Insurance Agency, LLC (doing business as GeoBlue) reported a data breach affecting international health insurance plan enrollees. Between October 11 and 13, 2017, unauthorized parties obtained employee email credentials via a phishing scheme. The attacker may have accessed emails containing enrollee names. No evidence of misuse was found. Remediation included forensic investigation, employee phishing training, enhanced email security software, and MFA implementation. Affected individuals were offered one year of Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136424
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 21, 2018
- Raw hash
- b684cd8fdb20aa91c3c9377e0ddd9f9d2be9cb2a20ed463910de84bc9bfbf5ff
Reporting entity
- Name
- WORLDWIDE INSURANCE SERVICES, LLCnorm: worldwide insurance
Victim entity
- Name
- WORLDWIDE INSURANCE SERVICES, LLCnorm: worldwide insurance
Incident
- Discovered
- Oct 13, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 31 weeks(220 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.