MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
Wright & Filippis
bd_53a6f924d343960c · schema v1 · pii pii-v1
Full breach record for Wright & Filippis →Wright & Filippis experienced a ransomware attack from January 26-28, 2022. The company's endpoint security terminated the malware, but unauthorized access may have occurred to files containing PHI and PII (names, DOB, SSN, financial account numbers, health insurance info). Notification was sent to affected patients and employees/applicants in multiple states on November 18, 2022. Remediation included EDR installation, password resets, and server rebuilds. Credit monitoring and ID theft protection were offered.
California clockDiscovered May 2, 2022 → Notified Nov 18, 2022200d ✗ CA 60-day late29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_09e527d6c1bad4a0Montana State AGfiled 2022-11-21(3d gap)Verified
- bd_f475484c5feae9feNew Hampshire State AGfiled 2022-11-28(10d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-559337
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2022
- Raw hash
- 84cb0f7dd629f329f136145e7d7becfeefee8d1dfcefb1f2fdc04743f8469e1a
Reporting entity
- Name
- Wright & Filippisnorm: wright filippis
- Domain
- firsttoserve.com
Victim entity
- Name
- Wright & Filippisnorm: wright filippis
- Domain
- firsttoserve.com
Incident
- Discovered
- May 2, 2022
- Materiality determined
- —
- Notification sent
- Nov 18, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Department of Justice - Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 weeks(200 days from discovery to filing)
- Compliance flags
- CA 60-day late · 200d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 2, 2022→ Notified: Nov 18, 2022200d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.