Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Institute for Integrative Nutrition
bd_65eda9899217f6a7 · schema v1 · pii pii-v1
Full breach record for Institute for Integrative Nutrition →Institute for Integrative Nutrition (IIN) disclosed a phishing incident in California where an unauthorized party accessed a single employee email account between March 3-4, 2020. The account contained names and Social Security numbers of individuals. IIN discovered the breach on June 22, 2020, secured the account, engaged forensic investigators, and offered one year of Experian IdentityWorks credit monitoring to affected individuals. No evidence of misuse was found.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193125
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2020
- Raw hash
- 3e108d3a8426339a27bcb811556544cfd80426e1a9ad2b4882834414f99485cf
Reporting entity
- Name
- Institute for Integrative Nutritionnorm: institute for integrative nutrition
- Domain
- integrativenutrition.com
Victim entity
- Name
- Institute for Integrative Nutritionnorm: institute for integrative nutrition
- Domain
- integrativenutrition.com
Incident
- Discovered
- Jun 22, 2020
- Materiality determined
- Jul 22, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.