Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CANTELLA & CO.,INC.
bd_386705a1849002e7 · schema v1 · pii pii-v1
Full breach record for CANTELLA & CO.,INC. →Cantella & Co., Inc. reported a data security incident on August 25, 2020, involving phishing emails with malicious attachments that installed malware on 23 company computers. The malware potentially exposed clients' names, addresses, and Social Security numbers. The company offered two years of complimentary credit monitoring and identity restoration services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-195984
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 10, 2020
- Raw hash
- d2ea92b05cf43980e5f2f9ed77e6dceacd23324b67ba35f386daf7aa2cc159b5
Reporting entity
- Name
- CANTELLA & CO.,INC.norm: cantella
- Domain
- cantella.com
Victim entity
- Name
- CANTELLA & CO.,INC.norm: cantella
- Domain
- cantella.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.001 Spearphishing AttachmentT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_attachment
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.