HackingFinancial ServicesProfessional ServicesFinanceCapture Stored DataExtortion DemandData ExfiltratedRansom DemandedRansom PaidData Leak ThreatenedCustomer Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Horizon Actuarial
bd_531852585f7aeb41 · schema v1 · pii pii-v1
Full breach record for Horizon Actuarial →Horizon Actuarial Services, LLC suffered an unauthorized access incident on November 10–11, 2021, in which an external group exfiltrated personal data from two company servers. The group notified Horizon on November 12, 2021 via email demanding payment. Horizon negotiated and paid the group, notified the FBI, and engaged third-party specialists. Affected data included PII of benefit plan participants. Notifications to affected individuals began January 13, 2022.
California clockDiscovered Nov 12, 2021 → Notified Jan 13, 202262d ✗ CA 60-day late30 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554163
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 9, 2022
- Raw hash
- c3d8afb401ece44742e39445869a3138c3667b6b2b126f3860c3a1f80acd4451
Reporting entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
Victim entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
- Industry
- Financial ServicesllmProfessional Servicesllm
Incident
- Discovered
- Nov 12, 2021
- Materiality determined
- —
- Notification sent
- Jan 13, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBIFiled notice with California Attorney General
Compliance
- Time to disclose
- 30 weeks(209 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 12, 2021→ Notified: Jan 13, 202262d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.