DisclosureLens
Social EngineeringHealthcareFinancial ServicesHealthcarePhishingStolen CredentialsTargetedMulti-Stage ChainIdentity (basic)Health (basic)LowActive

Cigna International Corporation

bd_612ad709126a067d · schema v1 · pii pii-v1

Severity

Low

Discovered

Sep 5, 2018

Filed

Oct 10, 2018

To disclose

5 weeks

Affected

6state residents only

Linked

3 filings

Confidence

66%
Full breach record for Cigna International Corporation5 incidents on file

Cigna Corporation disclosed a credential stuffing attack targeting the myCigna customer portal. Suspicious activity was detected on September 5, 2018, with unauthorized access continuing until September 24, 2018. Attackers used stolen credentials from other breaches to access accounts, potentially viewing names, contact info, and medical history. Cigna disabled accounts, engaged forensic investigators, and implemented MFA and IP blocking.

Incident timeline

discovery → filing · 5 weeks / 35 days

Sep 5, 2018

Begins

Sep 5, 2018

Discovered

Oct 10, 2018

Filed

vs. sector median

7 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
HHS OCROct 10 · first
Oregon State AGOct 10 · first
Montana State AGOct 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.