Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Supplemental Income Trust Fund; MonRoc Administrators LLC
bd_322bbee7734e9c4f · schema v1 · pii pii-v1
Full breach record for Supplemental Income Trust Fund; MonRoc Administrators LLC →Supplemental Income Trust Fund and MonRoc Administrators LLC reported a phishing incident occurring between March 22, 2021, and April 21, 2021. The breach compromised names and Social Security Numbers of 34,858 individuals, including 3 Maine residents. Discovered on April 25, 2021, the entity provided 24 months of credit monitoring via Experian IdentityWorks to affected consumers.
Maine clockDiscovered Apr 25, 2021 → Filed with AG Jun 1, 202137d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_52613eb173f9060bOregon State AGfiled 2021-06-03(2d gap)Verified
- bd_95e1ae162080a30fCalifornia State AGfiled 2021-06-03(2d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/0a6b92f5-587e-4a63-8791-bf2fc81da0a5.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2021
- Raw hash
- 184717a1a05afc389659ef9832f1de405709d20d1e8864a3996585dedda27481
Reporting entity
- Name
- SEYFARTH SHAW LLPnorm: seyfarth shaw
Victim entity
- Name
- Supplemental Income Trust Fund; MonRoc Administrators LLCnorm: supplemental income trust fund monroc administrators
Incident
- Discovered
- Apr 25, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 34,858
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- ME AG >30d · 37d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 25, 2021→ Filed with AG: Jun 1, 202137d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.