AccidentalMisdeliveryData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
AccessLex Institute
bd_252d53a7098baa46 · schema v1 · pii pii-v1
Full breach record for AccessLex Institute →AccessLex Institute d/b/a Access Group reported a data breach on March 28, 2018, involving a vendor error on March 23, 2018. A student loan processing vendor inadvertently sent loan files containing names, driver's license numbers, and Social Security numbers to an unauthorized business. The recipient deleted the files. AccessLex offered one year of Experian IdentityWorks credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-135410
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 18, 2018
- Raw hash
- 80be2856be7b355f6bbe5319456542bfb61755704d6f0e63be9a48877cf5e27d
Reporting entity
- Name
- AccessLex Institutenorm: accesslex institute
Victim entity
- Name
- AccessLex Institutenorm: accesslex institute
Incident
- Discovered
- Mar 28, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Initial access
- supply_chain
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.