HackingStolen CredentialsTargetedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
PlanMember Financial
bd_58d9e5f0a778fdd4 · schema v1 · pii pii-v1
Full breach record for PlanMember Financial →PlanMember Securities Corporation notified the California AG of a data breach discovered on March 15, 2022. Criminal actors illegally accessed an executive's email account to attempt wire fraud. Emails containing employee and client PII (SSNs, account numbers, names) were present in the compromised account. It is unknown if attackers accessed these attachments. PlanMember engaged forensic investigators, reported to law enforcement, and offered 12 months of identity theft protection.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_a4b2b687e3b8e7c1Montana State AGfiled 2022-07-01(2d gap)Verified
- bd_a44fc4621a30a1b2Maine State AGfiled 2022-06-27(2d gap)Verified
- bd_59916b7518e7d686California State AGfiled 2022-04-15(75d gap)Candidate
- bd_be1890f84a353419Washington State AGfiled 2022-04-15(75d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 79d gap
- bd_bf5c1abaa9187ec6Oregon State AGfiled 2022-04-15(75d gap)Verified
- bd_dd862f39ba8fd8b6New Hampshire State AGfiled 2022-04-11(79d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554732
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2022
- Raw hash
- dec27940a1ce1946588a2ed19ea643ef64577078ecdec4481275e994f3df074f
Reporting entity
- Name
- PlanMember Financialnorm: planmember financial
- Domain
- planmember.com
Victim entity
- Name
- PlanMember Financialnorm: planmember financial
- Domain
- planmember.com
Incident
- Discovered
- Mar 15, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the event to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.