Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Phase II Systems
bd_4b31bd974995f04f · schema v1 · pii pii-v1
Full breach record for Phase II Systems →Phase II Systems d/b/a PARS experienced a phishing incident where an unauthorized party accessed an employee's email account between March 11 and March 14, 2024. The compromised account contained personal information including full names and Social Security numbers. The company secured the account, engaged external cybersecurity professionals, and is offering credit monitoring to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8a77e6fdc10b4ce5Indiana State AGfiled 2024-08-28(1d gap)Verified
- bd_7c2b65795edf6bd6New Hampshire State AGfiled 2024-09-03(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-591001
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2024
- Raw hash
- b72d261b4a22428aff9bc19a84b474caa20c0fe582883a25d8c222d9d34a9d26
Reporting entity
- Name
- Phase II Systemsnorm: phase ii
Victim entity
- Name
- Phase II Systemsnorm: phase ii
Incident
- Discovered
- Mar 14, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 24 weeks(168 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.