Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
EyeMed Vision Benefits
bd_34d1a19c2cb74c79 · schema v1 · pii pii-v1
Full breach record for EyeMed Vision Benefits →Aetna (via EyeMed) reported a data breach affecting vision benefit recipients. An unauthorized individual accessed an EyeMed email mailbox on June 24, 2020, and sent phishing emails to the address book. Access was terminated on July 1, 2020. Personal information of individuals receiving vision benefits may have been viewed or copied. EyeMed engaged a cybersecurity firm, reset passwords, and provided two years of free identity monitoring via Kroll.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_dd7329e4945257eeDelaware State AGfiled 2020-12-11Verified
- bd_cf86ae44e1360d1cMaine State AGfiled 2020-11-30(11d gap)Verified
- bd_03f6bce6b4d9bc45South Carolina State AGfiled 2021-01-27(47d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197044
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2020
- Raw hash
- 46c671a2d7e9726ab72d1874dc69eb6066cc00d3f0d8d4a0691973f21573acaf
Reporting entity
- Name
- AETNA INC.norm: aetna
- Domain
- aetna.com
Victim entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Incident
- Discovered
- Jul 1, 2020
- Materiality determined
- Jun 24, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(163 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.