Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMINORMediumContained
Solara Medical Supplies
bd_4b5d01d262380952 · schema v1 · pii pii-v1
Full breach record for Solara Medical Supplies →Solara Medical Supplies, LLC reported a data breach affecting employee Office 365 accounts from April 2, 2019, to June 20, 2019. An unknown actor gained access via a phishing email campaign. The incident involved the potential access to employee and minor child personal information, including names, addresses, and government IDs. Solara engaged forensic experts, reset passwords, notified law enforcement and regulators, and offered 12 months of identity monitoring through Kroll.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_6f0c68498536cf4eMontana State AGfiled 2019-11-13Verified
- bd_7fe01d8193cf6304HHS OCRfiled 2019-11-13Verified
- bd_90fe4d22cd016ce0Oregon State AGfiled 2019-11-13Verified
- bd_c21b48af206410c4HHS OCRfiled 2020-01-17(65d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-184310
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2019
- Raw hash
- a65f93bfd8930ec93ee8d1ed598769893e45e9155f826fcf06f6c49409465dd3
Reporting entity
- Name
- Solara Medical Suppliesnorm: solara medical supplies
- Domain
- solara.com
Victim entity
- Name
- Solara Medical Suppliesnorm: solara medical supplies
- Domain
- solara.com
Incident
- Discovered
- Jun 28, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTMINOR
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified law enforcement of this incidentNotifying relevant state and federal regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 20 weeks(138 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.