CPT Group, Inc.
bd_4a1db9b56411442e · schema v1 · pii pii-v1
Full breach record for CPT Group, Inc. →2 incidents on fileCPT Group, Inc., a class action settlement administrator, notified the California Attorney General of a data breach. An unknown individual accessed an employee's email account from November 22, 2017, to December 8, 2017, following a phishing incident. CPT discovered the unauthorized access on February 8, 2018. Affected data may include names, addresses, and Social Security numbers of class members. CPT implemented multi-factor authentication and offered one year of identity monitoring through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 22, 2017
Begins
Feb 8, 2018
Discovered
Apr 27, 2018
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_8095bef0d2d971ef2018-04-30 · +3dVerified
- Delaware State AGbd_9d154eb6b5f6bc2e2018-05-08 · +11dVerified
- Montana State AGbd_c31e9c4116a195902018-05-08 · +11dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Apr 27 (CA), last May 8 (MT) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.