MalwarePhishingRansomwareRansom DemandedData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICIDENTITY_BASICMediumContained
Magellan Health
bd_34de5bda8012b71c · schema v1 · pii pii-v1
Full breach record for Magellan Health →Magellan Health, Inc. disclosed a ransomware attack discovered on April 11, 2020, following a phishing email on April 6, 2020. The incident compromised personal information including SSNs, financial data, and health records. Magellan engaged Mandiant for forensics, notified the FBI, and offered credit monitoring. No specific victim count was provided in the filing.
California clockDiscovered Apr 11, 2020 → Notified Jun 15, 202065d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_8bced8d5ed3979b9HHS OCRfiled 2020-06-12Verified
- bd_9e737f4798eb5a36South Carolina State AGfiled 2020-05-12(31d gap)Verified
- bd_5bd5952fe83a4024Oregon State AGfiled 2020-05-11(32d gap)Candidate
- bd_ab19fc861c82e826California State AGfiled 2020-05-11(32d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 32d gap
- bd_ae473065eafe4312Montana State AGfiled 2020-05-11(32d gap)Verified
- bd_c7cf9063b0b75322Washington State AGfiled 2020-05-11(32d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190863
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2020
- Raw hash
- ecd86b33a77f585acbd670f31c083de76669ce3b67568768eed8b879970ad13f
Reporting entity
- Name
- Magellan Healthnorm: magellan health
- Domain
- magellanhealth.com
Victim entity
- Name
- Magellan Healthnorm: magellan health
- Domain
- magellanhealth.com
Incident
- Discovered
- Apr 11, 2020
- Materiality determined
- —
- Notification sent
- Jun 15, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- CA 60-day late · 65d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 11, 2020→ Notified: Jun 15, 202065d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.