HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Compex Legal Services
bd_27ddf809b97c17ee · schema v1 · pii pii-v1
Full breach record for Compex Legal Services →Compex Legal Services Inc. disclosed unauthorized access to its network occurring between April 9 and April 19, 2024, discovered on April 17, 2024. An unknown actor acquired certain files. The company provides medical record retrieval services for law firms and insurance carriers. Affected data may include PII, PHI, and government IDs. The company engaged third-party cybersecurity specialists, notified law enforcement, and offered credit monitoring.
Leak gap clock⏱ Leak >90d19 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0588ccacc7611641Leak Sitecl0pfiled 2024-05-04(117d gap)Verified
Regulatory filings (4) · sorted by filing gap
- bd_0e0c8e276e11a0dcVermont State AGfiled 2024-08-29(1d gap)Verified
- bd_37494d5f18dc2ef3California State AGfiled 2024-07-24(37d gap)Verified
- bd_953495f025c39606Wisconsin State AGfiled 2024-07-24(37d gap)Verified
- bd_d56b2efa27580456California State AGfiled 2024-10-25(56d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-591073
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2024
- Raw hash
- f48a42e8a09d175c4fd2c20ea493349c23db8d9367f1adccfa6c8067c0cd9652
Reporting entity
- Name
- Compex Legal Servicesnorm: compex legal
- Domain
- compexlegal.com
Victim entity
- Name
- Compex Legal Servicesnorm: compex legal
- Domain
- compexlegal.com
Incident
- Discovered
- Apr 17, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the event to law enforcement
Compliance
- Time to disclose
- 19 weeks(135 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.