HackingStolen CredentialsTargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Bankers Life and Casualty Company
bd_3db61e65232ceb3b · schema v1 · pii pii-v1
Full breach record for Bankers Life and Casualty Company →Bankers Life and Casualty Company disclosed a breach involving a SIM swapping attack on a senior officer's cellular account. The threat actor bypassed multi-factor authentication to access company data, including customer names, SSNs, dates of birth, and policy numbers. The incident was discovered on November 29, 2023. The company engaged law enforcement and forensic investigators, contained the access, and offered identity protection services.
California clockDiscovered Nov 29, 2023 → Notified Jan 26, 202458d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_6ad88753f461a26fOregon State AGfiled 2024-01-29Verified
- bd_489763d38fcd7db5Montana State AGfiled 2024-01-30(1d gap)Verified
- bd_7279c81e38952fbaWashington State AGfiled 2024-01-30(1d gap)Verified
- bd_ceb4c165523f0761Maine State AGfiled 2024-01-30(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_f5b10da171539b6bNew Hampshire State AGScattered Spiderfiled 2024-01-30(1d gap)Verified
- bd_e963eb59f735e937Indiana State AGfiled 2024-01-26(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580119
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2024
- Raw hash
- c0cd43261684bc5419d4a7325b9f6e6ab7466d5216c48164708d383464cf7776
Reporting entity
- Name
- Bankers Life and Casualty Companynorm: bankers life and casualty
Victim entity
- Name
- Bankers Life and Casualty Companynorm: bankers life and casualty
Incident
- Discovered
- Nov 29, 2023
- Materiality determined
- —
- Notification sent
- Jan 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcementBegan working with the Federal Bureau of InvestigationBegan working with the Offices of the United States Attorneys
- Third party
- via Wireless carrier retailer
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 58d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 29, 2023→ Notified: Jan 26, 202458d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.