Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENTMediumContained
Mitchell International, Inc.
bd_24a4835c745f2af6 · schema v1 · pii pii-v1
Full breach record for Mitchell International, Inc. →Mitchell International, Inc. reported a data breach to the California Attorney General on March 11, 2016, involving a phishing incident on February 24, 2016. An unauthorized actor impersonated executive leadership to trick an employee into disclosing personal information of current and former employees, including names, SSNs, and salaries. No customer data or network intrusion occurred. Mitchell notified the AG, engaged AllClear ID for two years of identity protection services, and provided employee security training.
California clockDiscovered Mar 3, 2016 → Notified Mar 11, 20168d ✓ CA 60-day OK11 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60473
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2016
- Raw hash
- 237c352aab3ccc35face2b9cf0955abb7a8fefefd4b64307237c64bf9eaa19c8
Reporting entity
- Name
- Mitchell International, Inc.norm: mitchell international
Victim entity
- Name
- Mitchell International, Inc.norm: mitchell international
Incident
- Discovered
- Mar 3, 2016
- Materiality determined
- —
- Notification sent
- Mar 11, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided a sample copy of this letter (without any of your identifying information) to the California Attorney General’s office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 8d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 3, 2016→ Notified: Mar 11, 20168d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.