HackingFinancial ServicesProfessional ServicesFinanceCapture Stored DataExtortion DemandData ExfiltratedRansom DemandedRansom PaidData Leak ThreatenedCustomer Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
Horizon Actuarial
bd_53d47d81dff4b4e3 · schema v1 · pii pii-v1
Full breach record for Horizon Actuarial →On November 10-11, 2021, unauthorized actors accessed two Horizon Actuarial Services computer servers and exfiltrated personal data related to benefit plan participants. On November 12, 2021, the company received an extortion email. Horizon Actuarial paid the group in exchange for deletion of stolen data. Affected data may include PII of benefit plan participants. The company notified the FBI, engaged third-party specialists, and arranged 12 months of Kroll identity monitoring for affected individuals.
California clockDiscovered Nov 12, 2021 → Notified Jan 13, 202262d ✗ CA 60-day late22 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_eee334be4ae16c8eCalifornia State AGfiled 2022-04-11(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552651
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 15, 2022
- Raw hash
- fe437498295410313b7db12e6db47d179e74e97dd9ae9109c88f056df430536b
Reporting entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
Victim entity
- Name
- Horizon Actuarialnorm: horizon actuarial
- Domain
- horizonactuarial.com
- Industry
- Financial ServicesllmProfessional Servicesllm
Incident
- Discovered
- Nov 12, 2021
- Materiality determined
- —
- Notification sent
- Jan 13, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 ChannelT1074 Data Staged
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI
Compliance
- Time to disclose
- 22 weeks(154 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 12, 2021→ Notified: Jan 13, 202262d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.