HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
LIBERTY MUTUAL GROUP INC.
bd_2d94f08bebeefcf7 · schema v1 · pii pii-v1
Full breach record for LIBERTY MUTUAL GROUP INC. →Liberty Mutual Group, Inc. reported unauthorized third-party access to its public websites (LibertyMutual.com and GetCertainly.com) between November 2020 and March 2021. The actor submitted fraudulent auto insurance quotes to access victims' driver's license numbers, names, and dates of birth. Liberty Mutual detected the activity in January and March 2021, removed the vulnerability, reported the incident to authorities, and offered credit monitoring services to affected individuals.
California clockDiscovered Jan 21, 2021 → Notified Apr 1, 202170d ✗ CA 60-day late10 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d1628612bddc4dbfOregon State AGfiled 2021-03-31(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539606
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2021
- Raw hash
- f67d548f6e203c07f35c2c33ed316a6b8dbac362963abf7b867cf08e45eb69a2
Reporting entity
- Name
- LIBERTY MUTUAL GROUP INC.norm: liberty mutual
Victim entity
- Name
- LIBERTY MUTUAL GROUP INC.norm: liberty mutual
Incident
- Discovered
- Jan 21, 2021
- Materiality determined
- —
- Notification sent
- Apr 1, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to the authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- CA 60-day late · 70d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 21, 2021→ Notified: Apr 1, 202170d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.