Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Abode Services
bd_5820170fc88d4399 · schema v1 · pii pii-v1
Full breach record for Abode Services →Abode Services, a healthcare services provider, notified California residents of a data breach occurring between March 16, 2021, and April 15, 2021. An unauthorized third party accessed employee email accounts, potentially exposing client names, addresses, dates of birth, Social Security numbers, medical information, and financial data. Abode engaged forensic investigators, reset passwords, enabled two-factor authentication, and filed an FBI report. Affected individuals were offered one year of identity monitoring through Kroll.
California clockDiscovered Apr 15, 2021 → Notified Apr 15, 20210d ✓ CA 60-day OK17 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_eba09dfe49c0c583California State AGfiled 2021-06-25(45d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543702
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2021
- Raw hash
- f33a0f279a57d1c0f7e209af881c34cfe58d775d22372b91bb5f8389e42eb961
Reporting entity
- Name
- Abode Servicesnorm: abode services
Victim entity
- Name
- Abode Servicesnorm: abode services
Incident
- Discovered
- Apr 15, 2021
- Materiality determined
- —
- Notification sent
- Apr 15, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Filed a report with the FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 15, 2021→ Notified: Apr 15, 20210d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.