Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICHighActive
Welk Resort Group, Inc.
bd_4232e60c18c6f6d0 · schema v1 · pii pii-v1
Full breach record for Welk Resort Group, Inc. →Welk Resort Group, Inc. reported a data breach affecting approximately 1,034 California residents. Unauthorized actors gained access to employee email accounts between November 29 and December 4, 2017, via phishing. Personal information including names, SSNs, driver's licenses, financial account data, and medical history was present in the compromised emails. No evidence of misuse was found. The company engaged forensic investigators and offered 12 months of credit monitoring.
California clockDiscovered Dec 4, 2017 → Notified Jul 25, 2018233d ✗ CA 60-day late34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e646fad2217cff73Montana State AGfiled 2018-07-25(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-138441
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2018
- Raw hash
- 6439df789a77d4e4cf93e5ea68fe42f328992788fcd27caa2410c87cd77feff9
Reporting entity
- Name
- Welk Resort Group, Inc.norm: welk resort
Victim entity
- Name
- Welk Resort Group, Inc.norm: welk resort
Incident
- Discovered
- Dec 4, 2017
- Materiality determined
- —
- Notification sent
- Jul 25, 2018
- Affected individuals
- 1,034
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Providing notice to California regulators as required by law
- Initial access
- phishing_link
Compliance
- Time to disclose
- 34 weeks(240 days from discovery to filing)
- Compliance flags
- CA 60-day late · 233d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 4, 2017→ Notified: Jul 25, 2018233d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.