Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
BIOMARIN PHARMACEUTICAL INC.
bd_2a9bee3fa04b251f · schema v1 · pii pii-v1
Full breach record for BIOMARIN PHARMACEUTICAL INC. →BioMarin Pharmaceutical Inc. disclosed a phishing incident in California where an attacker accessed two email accounts using a temporary employee's stolen credentials. The breach exposed names, Social Security Numbers, and health insurance policy numbers. BioMarin contained the breach by changing credentials and offered one year of LifeLock identity protection to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-140662
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 11, 2018
- Raw hash
- 332e01ef85434082cfcf87ca124d15f13887701069026af1f8740b17ac570f96
Reporting entity
- Name
- BIOMARIN PHARMACEUTICAL INC.norm: biomarin pharmaceutical
- Domain
- biomarin.com
Victim entity
- Name
- BIOMARIN PHARMACEUTICAL INC.norm: biomarin pharmaceutical
- Domain
- biomarin.com
Incident
- Discovered
- Jun 21, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.