MalwareRansomwareData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
First Financial Sercurity, Inc.
bd_4d924f83378dd373 · schema v1 · pii pii-v1
Full breach record for First Financial Sercurity, Inc. →First Financial Security, Inc. experienced a ransomware attack on October 17, 2023. The attack was discovered on the same day. A limited amount of system data was exposed, including full names, personal information, and social security numbers of life insurance agents and customers. The company engaged outside IT security experts, contained the incident, and is offering identity monitoring services through IDX.
California clockDiscovered Oct 17, 2023 → Notified Jan 19, 202494d ✗ CA 60-day late13 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_c0dc65dca43d10baIndiana State AGfiled 2024-01-19Verified
- bd_3cce2402d8d3ade9California State AGfiled 2024-01-22(3d gap)Verified
- bd_be68a4e3fb13fb6aNew Hampshire State AGfiled 2024-01-22(3d gap)Verified
- bd_376c075094fa399aSouth Carolina State AGfiled 2024-01-23(4d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 16d gap
- bd_d5e7a15eb37ead79Oregon State AGfiled 2024-01-23(4d gap)Verified
- bd_e247aee4a995db93Montana State AGfiled 2024-01-23(4d gap)Verified
- bd_aff224a399f38befWashington State AGfiled 2024-01-03(16d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579609
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 19, 2024
- Raw hash
- a2726ba46beba2d24464de321d8c16f8f6515dea18d5589672527ca41e33e9f9
Reporting entity
- Name
- First Financial Sercurity, Inc.norm: first financial sercurity
- Domain
- firstfinancialsecurity.com
Victim entity
- Name
- First Financial Sercurity, Inc.norm: first financial sercurity
- Domain
- firstfinancialsecurity.com
Incident
- Discovered
- Oct 17, 2023
- Materiality determined
- —
- Notification sent
- Jan 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 13 weeks(94 days from discovery to filing)
- Compliance flags
- CA 60-day late · 94dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 17, 2023→ Notified: Jan 19, 202494d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.