Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
HUMANA INC.
bd_340755f98cffa704 · schema v1 · pii pii-v1
Full breach record for HUMANA INC. →Humana Inc. notified the New Hampshire Attorney General of a security incident involving its law firm, Pillsbury Winthrop Shaw Pitman LLP. In April 2025, Pillsbury was targeted by social engineering (phishing). An unauthorized actor downloaded Humana litigation documents containing PHI, PII, and financial data. Discovery occurred in December 2025. One NH resident was affected. Notifications were sent in June 2026, offering 24 months of credit monitoring.
Leak gap clock✗ Leak >180d28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
A leak claim by cl0p about this victim predates this filing by 202 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pillsbury-winthrop-shaw-pitman-20260612.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2026
- Raw hash
- 6c9300e696c5e8a049687bca256a046de6187810f063d38c32391bef237c2680
Reporting entity
- Name
- PILLSBURY WINTHROP SHAW PITTMAN LLPnorm: pillsbury winthrop shaw pittman
Victim entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
Incident
- Discovered
- Dec 1, 2025
- Materiality determined
- —
- Notification sent
- Jun 1, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 weeks(193 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.