DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDMediumContained

SEIU 32BJ

bd_6299bc29b40e8a7f · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 18, 2018

Filed

May 26, 2018

To disclose

8 days

Affected

Not disclosed

Linked

4 filings

Confidence

65%
Full breach record for SEIU 32BJ2 incidents on file

SEIU Local 32BJ disclosed a phishing incident occurring November 13-14, 2017, where an employee's email account was compromised via an externally-hosted email management system. The breach exposed members' full names and Social Security numbers. The union engaged external cybersecurity experts, enhanced security protocols (MFA, password updates), and offered one year of free credit monitoring via Experian IdentityWorks to affected individuals. Notification letters were sent on May 24, 2018.

Incident timeline

undetected · 186 days
discovery → filing · 8 days

Nov 13, 2017

Begins

May 18, 2018

Discovered

May 26, 2018

Filed

vs. sector median

16 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Montana State AGMay 25 · first
New Hampshire State AGMay 25 · first
Delaware State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.