Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Phase II Systems
bd_60977085899ddf66 · schema v1 · pii pii-v1
Full breach record for Phase II Systems →Phase II Systems d/b/a PARS disclosed a phishing incident where an unauthorized party accessed an employee's email account between March 31 and May 24, 2021. The breach exposed names and other personal information. PARS secured the account, engaged forensic investigators, and offered 12 months of credit monitoring via TransUnion. No evidence of misuse was found.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-549033
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 31, 2021
- Raw hash
- 6be751ccfe36984c4c3dced5d392e50fcd659958e550c9b0b5105d6286b69133
Reporting entity
- Name
- Phase II Systemsnorm: phase ii
Victim entity
- Name
- Phase II Systemsnorm: phase ii
Incident
- Discovered
- Nov 28, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.