Social EngineeringPhishingCustomer Data InvolvedPIIPHIIDENTITY_BASICLowContained
INSURANCE OFFICE OF AMERICA, INC.
bd_4c989eca675e1207 · schema v1 · pii pii-v1
Full breach record for INSURANCE OFFICE OF AMERICA, INC. →Insurance Office of America (IOA) disclosed a data breach discovered on June 30, 2025, resulting from a phishing email attack. Unauthorized access occurred between June 25 and June 30, 2025. Affected data includes personally identifiable information (name) and potentially protected health information. IOA engaged external cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring via Epiq.
Leak gap clock⏱ Leak >90d29 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e3c12e2f5899425bLeak Sitedaixinfiled 2025-09-11(127d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_d25c427318091937Maine State AGfiled 2026-01-16Candidate
- bd_23b7cd8d3b9c09b1Texas State AGfiled 2026-01-21(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-617219
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2026
- Raw hash
- 06188174432e27e29da588415cea48b92ef890ba5b5e629368355fa89fda6232
Reporting entity
- Name
- INSURANCE OFFICE OF AMERICA, INC.norm: insurance office of america
- Domain
- ioausa.com
Victim entity
- Name
- INSURANCE OFFICE OF AMERICA, INC.norm: insurance office of america
- Domain
- ioausa.com
Incident
- Discovered
- Jun 30, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 29 weeks(200 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.