OneDigital Investment Advisors LLC
bd_5a1b88518f9bfe89 · schema v1 · pii pii-v1
Full breach record for OneDigital Investment Advisors LLC →OneDigital Investment Advisors LLC notified customers of a data security event involving a third-party application. Between August 12-18, 2025, an unauthorized actor potentially accessed and copied customer data stored in Salesforce due to a compromise of the Drift application (managed by Salesloft). OneDigital was notified by Salesforce on August 22, 2025. The incident did not involve a compromise of OneDigital's internal network. Affected data includes names and other personal information. OneDigital engaged forensic specialists, confirmed system security, and is offering credit monitoring.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_16dcd2a6a721552eWashington State AGfiled 2026-04-08Candidate
- bd_17257010d9a4d51aMaine State AGfiled 2026-04-08Verified
- bd_616a7eca5bff3650New Hampshire State AGfiled 2026-04-08Verified
- bd_89c363698f4bb715Indiana State AGfiled 2026-04-08Verified
Show 3 more filings ↓Show fewer ↑up to 12d gap
- bd_a8e53b1611378d44Vermont State AGfiled 2026-04-08Verified
- bd_ed2c8dae469e2d8bTexas State AGfiled 2026-04-10(2d gap)Verified by operator
- bd_2634d621d74802adOregon State AGfiled 2026-04-20(12d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621499
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2026
- Raw hash
- e63ab6d5499ec31e449039fecdd07bdd9fd0f113fed28a101ee7abf2978e5724
Reporting entity
- Name
- OneDigital Investment Advisors LLCnorm: onedigital investment advisors
- Domain
- onedigital.com
Victim entity
- Name
- OneDigital Investment Advisors LLCnorm: onedigital investment advisors
- Domain
- onedigital.com
Incident
- Discovered
- Aug 22, 2025
- Materiality determined
- —
- Notification sent
- Apr 8, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 33 weeks(229 days from discovery to filing)
- Compliance flags
- CA 60-day late · 229dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 22, 2025→ Notified: Apr 8, 2026229d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Apr 8, 2026→ AG copy submitted: Apr 8, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.