HackingStolen CredentialsTargetedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PlanMember Financial
bd_59916b7518e7d686 · schema v1 · pii pii-v1
Full breach record for PlanMember Financial →PlanMember Securities Corporation experienced a targeted cyber incident where criminal actors illegally accessed an executive's email account to attempt wire fraud. The attackers may have accessed attached documents containing employee and client PII, including names, Social Security numbers, and account numbers. The breach occurred on February 17, 2022, and was discovered on March 15, 2022. PlanMember engaged forensic investigators, notified law enforcement, and is offering 12 months of identity theft protection to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_be1890f84a353419Washington State AGfiled 2022-04-15Verified
- bd_bf5c1abaa9187ec6Oregon State AGfiled 2022-04-15Verified
- bd_dd862f39ba8fd8b6New Hampshire State AGfiled 2022-04-11(4d gap)Verified
- bd_a44fc4621a30a1b2Maine State AGfiled 2022-06-27(73d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 77d gap
- bd_58d9e5f0a778fdd4California State AGfiled 2022-06-29(75d gap)Verified
- bd_a4b2b687e3b8e7c1Montana State AGfiled 2022-07-01(77d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552652
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 15, 2022
- Raw hash
- 7360be93c9ac9edd620805655f3e69edca9df285c0c66d5af0ab4065d231391e
Reporting entity
- Name
- PlanMember Financialnorm: planmember financial
- Domain
- planmember.com
Victim entity
- Name
- PlanMember Financialnorm: planmember financial
- Domain
- planmember.com
Incident
- Discovered
- Mar 15, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the event to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.