Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
SEIU 32BJ
bd_6299bc29b40e8a7f · schema v1 · pii pii-v1
Full breach record for SEIU 32BJ →SEIU Local 32BJ disclosed a phishing incident occurring November 13-14, 2017, where an employee's email account was compromised via an externally-hosted email management system. The breach exposed members' full names and Social Security numbers. The union engaged external cybersecurity experts, enhanced security protocols (MFA, password updates), and offered one year of free credit monitoring via Experian IdentityWorks to affected individuals. Notification letters were sent on May 24, 2018.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2018/06/SEUI-Local-32BJ-Sample-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2018
- Raw hash
- 8be680b938e5062699532e5ecd1c5f0aef386530dc62b8d4958fb2e327c3009a
Reporting entity
- Name
- SEIU 32BJnorm: seiu 32bj
Victim entity
- Name
- SEIU 32BJnorm: seiu 32bj
Incident
- Discovered
- May 18, 2018
- Materiality determined
- —
- Notification sent
- May 24, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.