Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
Superior Vision
bd_68a6283795a0a0cf · schema v1 · pii pii-v1
Full breach record for Superior Vision →Superior Vision Services, Inc. (a subsidiary of Versant Health) experienced a phishing attack on July 9, 2025, targeting an employee. On July 11, 2025, the threat actor may have downloaded emails containing customer personal information, including names, addresses, SSNs, and employment data. The company disabled the account, secured systems, and notified law enforcement. Affected individuals are offered one year of credit monitoring.
California clockDiscovered Jul 11, 2025 → Notified Sep 26, 202577d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_bc2272cfff8e4237HHS OCRfiled 2025-09-29Verified
- bd_29804289e100ae59Texas State AGfiled 2025-10-01(2d gap)Verified
- bd_395d5bfe07979c7aNew Hampshire State AGfiled 2025-09-26(3d gap)Verified
- bd_b5421b1d9a69aad9Indiana State AGfiled 2025-09-26(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-610774
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2025
- Raw hash
- 7f93ee8c0ebdfc0b4927a162fa9f2720c209407839dc6e948f7f9276336ed074
Reporting entity
- Name
- Superior Visionnorm: superior vision
- Domain
- superiorvision.com
Victim entity
- Name
- Superior Visionnorm: superior vision
- Domain
- superiorvision.com
Incident
- Discovered
- Jul 11, 2025
- Materiality determined
- —
- Notification sent
- Sep 26, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- CA 60-day late · 77d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 11, 2025→ Notified: Sep 26, 202577d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.