DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingTargetedData ExfiltratedIdentity (basic)Government IDFinancial accountIP / systemMediumContained

Portola Partners Group

bd_44a1337c53344038 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 8, 2020

Filed

Oct 6, 2020

To disclose

28 days

Affected

2state residents only

Linked

2 filings

Confidence

66%
Full breach record for Portola Partners Group

Portola Partners Group notified Montana residents of a phishing incident on September 8, 2020. A single employee's computer was infected via a malicious link in a reply to an existing email thread. The malware could capture screenshots and steal credentials. Affected data included client names, SSNs, bank account numbers, DOBs, and government IDs. No evidence of actual misuse was found, but compromise could not be ruled out. Forensic investigation was conducted, law enforcement notified, and 10 years of credit monitoring offered.

Incident timeline

discovery → filing · 28 days

Sep 8, 2020

Begins

Sep 8, 2020

Discovered

Oct 6, 2020

Filed

vs. sector median

5 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Montana State AGOct 6 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.