DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsEmployee Data InvolvedMulti-Stage ChainIdentity (basic)Government IDEmploymentFinancial accountHighContained

TERMINIX GLOBAL HOLDINGS, INC.

bd_63678ffc75ec207d · schema v1 · pii pii-v1

Severity

High

Discovered

Sep 16, 2020

Filed

Oct 9, 2020

To disclose

23 days

Affected

14,708

Linked

4 filings

Confidence

66%
Full breach record for TERMINIX GLOBAL HOLDINGS, INC.3 incidents on file

Terminix Global Holdings disclosed that a teammate responded to a phishing scam, allowing hackers to access an Office 365 account and auto-forward emails from September 10 to September 22, 2020. The breach affected 14,708 current and former employees nationwide, exposing names, SSNs, dates of birth, employment dates, and 401K balances. The company contained the breach, disabled forwarding, and offered two years of identity theft protection.

Incident timeline

undetected · 6 days
discovery → filing · 23 days

Sep 10, 2020

Begins

Sep 16, 2020

Discovered

Oct 9, 2020

Filed

vs. sector median

14 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGOct 9 · first
California State AGOct 9 · first · this page

Pattern: first filing Oct 9 (IN), last Oct 19 (NH) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.