Cigna International Corporation
bd_612ad709126a067d · schema v1 · pii pii-v1
Full breach record for Cigna International Corporation →5 incidents on fileCigna Corporation disclosed a credential stuffing attack targeting the myCigna customer portal. Suspicious activity was detected on September 5, 2018, with unauthorized access continuing until September 24, 2018. Attackers used stolen credentials from other breaches to access accounts, potentially viewing names, contact info, and medical history. Cigna disabled accounts, engaged forensic investigators, and implemented MFA and IP blocking.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 5, 2018
Begins
Sep 5, 2018
Discovered
Oct 10, 2018
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_03b11a85be97a5192018-10-10Verified
- Oregon State AGbd_6a96bd75470b3b2d2018-10-10Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.