HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICHighContained
CSI FINANCIAL SERVICES, LLC
bd_49e91b979f4d88a9 · schema v1 · pii pii-v1
Full breach record for CSI FINANCIAL SERVICES, LLC →CSI Financial Services, LLC (ClearBalance) reported a data breach affecting approximately 15,000 individuals. Unauthorized access to email accounts occurred between March 8, 2021, and April 26, 2021. The incident exposed personal information including names, SSNs, dates of birth, government IDs, financial account details, and clinical/health insurance information. The company engaged forensic investigators, notified the FBI, reset passwords, and offered 24 months of identity theft protection services.
California clockDiscovered Apr 26, 2021 → Notified Jul 9, 202174d ✗ CA 60-day late11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1dcc6aa2da29562fMaine State AGfiled 2021-07-09Candidate
- bd_89f3f650d56ba9f1Montana State AGfiled 2021-07-09Verified
- bd_9e9c1a7959695185Washington State AGfiled 2021-07-09Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542757
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 9, 2021
- Raw hash
- 846cc609659f9d4f8c8359f09470774564476b98495cf032e7b1245076fec277
Reporting entity
- Name
- CSI FINANCIAL SERVICES, LLCnorm: csi financial
Victim entity
- Name
- CSI FINANCIAL SERVICES, LLCnorm: csi financial
Incident
- Discovered
- Apr 26, 2021
- Materiality determined
- —
- Notification sent
- Jul 9, 2021
- Affected individuals
- 15,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted the FBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- CA 60-day late · 74d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 26, 2021→ Notified: Jul 9, 202174d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.