MalwareRansomwareCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
First Financial Sercurity, Inc.
bd_3cce2402d8d3ade9 · schema v1 · pii pii-v1
Full breach record for First Financial Sercurity, Inc. →First Financial Security, Inc. experienced a ransomware attack on October 17, 2023. The attack was discovered on the same day. A limited amount of system data was exposed, including full names, personal information, and social security numbers of life insurance agents and customers. The company engaged IDX for identity monitoring services and enhanced its security systems.
California clockDiscovered Oct 17, 2023 → Notified Jan 19, 202494d ✗ CA 60-day late14 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_be68a4e3fb13fb6aNew Hampshire State AGfiled 2024-01-22Verified
- bd_376c075094fa399aSouth Carolina State AGfiled 2024-01-23(1d gap)Verified
- bd_d5e7a15eb37ead79Oregon State AGfiled 2024-01-23(1d gap)Verified
- bd_e247aee4a995db93Montana State AGfiled 2024-01-23(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 19d gap
- bd_4d924f83378dd373California State AGfiled 2024-01-19(3d gap)Verified
- bd_c0dc65dca43d10baIndiana State AGfiled 2024-01-19(3d gap)Verified
- bd_aff224a399f38befWashington State AGfiled 2024-01-03(19d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579693
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 22, 2024
- Raw hash
- 8eedf6ee6be8bd9a0859b9c3eff4777e54ff035df6409c0d0af1f98f6c88d76c
Reporting entity
- Name
- First Financial Sercurity, Inc.norm: first financial sercurity
- Domain
- firstfinancialsecurity.com
Victim entity
- Name
- First Financial Sercurity, Inc.norm: first financial sercurity
- Domain
- firstfinancialsecurity.com
Incident
- Discovered
- Oct 17, 2023
- Materiality determined
- —
- Notification sent
- Jan 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- CA 60-day late · 94dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 17, 2023→ Notified: Jan 19, 202494d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.