MalwareRansomwareData EncryptedRansom DemandedIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTLowContained
Reprosource
bd_60815a0ad2f2fb25 · schema v1 · pii pii-v1
Full breach record for Reprosource →ReproSource Fertility Diagnostics, Inc. reported a ransomware incident on August 8, 2021. The attacker accessed the network, and ransomware was discovered on August 10. The company contained the incident, engaged forensic experts, and notified law enforcement. While data acquisition was not confirmed, personal information including names, addresses, DOBs, and health/financial data may have been accessed. Affected individuals were offered one year of credit monitoring via Kroll.
California clockDiscovered Aug 10, 2021 → Notified Sep 24, 202145d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1a0eb1fd9490ea83Montana State AGfiled 2021-10-08Verified
- bd_28c673547fd8171aSouth Carolina State AGfiled 2021-10-08Verified
- bd_b67f67fff80c97a8Washington State AGfiled 2021-10-08Verified
- bd_ceb1810a1a430219Delaware State AGfiled 2021-10-08Verified
Show 2 more filings ↓Show fewer ↑
- bd_f8be3bea8117c449Oregon State AGfiled 2021-10-08Verified
- bd_fd7dc0062bcdb4afHHS OCRfiled 2021-10-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-546267
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 8, 2021
- Raw hash
- 5b2e4f5628d2cb5b012132e292b394298bd3a2d1ea74bf2abad2437a49d6458b
Reporting entity
- Name
- Reprosourcenorm: reprosource
- Domain
- reprosource.com
Victim entity
- Name
- Reprosourcenorm: reprosource
- Domain
- reprosource.com
Incident
- Discovered
- Aug 10, 2021
- Materiality determined
- —
- Notification sent
- Sep 24, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 45d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 10, 2021→ Notified: Sep 24, 202145d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.