HackingSupply Chain (3P Vendor)Customer Data InvolvedPIIPHIIDENTITY_BASICLowContained
NationsBenefits Holdings, LLC
bd_5cf8474b7cde8f07 · schema v1 · pii pii-v1
Full breach record for NationsBenefits Holdings, LLC →NationsBenefits Holdings, LLC notified California residents that a third-party vendor, Fortra, LLC, experienced a cybersecurity incident on or around January 30, 2023. NationsBenefits learned of the incident on February 7, 2023. The attack involved unauthorized access to data exchanged via Fortra's software. NationsBenefits stopped using the software, engaged forensic investigators, and notified law enforcement. Affected individuals were offered 24 months of identity monitoring.
California clockDiscovered Feb 7, 2023 → Notified Apr 13, 202365d ✗ CA 60-day late9 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1b538b7a6b069a1eVermont State AGfiled 2023-04-13(1d gap)Verified
- bd_27eb698b3f802e52Montana State AGfiled 2023-04-13(1d gap)Candidate
- bd_7a3042e338cc1200New Hampshire State AGfiled 2023-04-13(1d gap)Verified
- bd_e00425fe19d51b10Delaware State AGfiled 2023-04-13(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 21d gap
- bd_90ff9cd7813fad7cOregon State AGfiled 2023-05-01(17d gap)Verified
- bd_be7b07047f2e066aMaine State AGfiled 2023-05-05(21d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565565
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2023
- Raw hash
- 814310cbe5a77c97d402d1a3ac2339499c35551fbd288bd1875a66123d429ee0
Reporting entity
- Name
- NationsBenefits Holdings, LLCnorm: nationsbenefits holdings
Victim entity
- Name
- NationsBenefits Holdings, LLCnorm: nationsbenefits holdings
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- —
- Notification sent
- Apr 13, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Fortra, LLC
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- CA 60-day late · 65d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 7, 2023→ Notified: Apr 13, 202365d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.