Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedCREDENTIALSPIILowContained
UNUM GROUP
bd_4eb9e51de187d4a9 · schema v1 · pii pii-v1
Full breach record for UNUM GROUP →Unum Group notified Delaware residents of a cybersecurity incident where an unknown actor accessed an employee's email account between Oct 28 and Nov 15, 2021. Unum discovered the breach on Nov 23, 2021. The incident involved unauthorized access to email credentials, potentially exposing customer PII. Unum secured the account, enhanced email security, and offered 24 months of credit monitoring via Experian.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_bb17019b8fea9cc0Oregon State AGfiled 2022-01-28Candidate
- bd_ff9aff859f75440fCalifornia State AGfiled 2022-01-28Verified
- bd_707b54a4c14096baWashington State AGfiled 2022-01-31(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/02/Unum-Individual-Notification-Template.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 28, 2022
- Raw hash
- b5b90cc1c63a6bec70870f57366c155cac4449a810f9dc8aa34ff98538ed58e3
Reporting entity
- Name
- UNUM GROUPnorm: unum group
Victim entity
- Name
- UNUM GROUPnorm: unum group
Incident
- Discovered
- Nov 23, 2021
- Materiality determined
- —
- Notification sent
- Jan 28, 2022
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.