BSI Financial Services
bd_68d65420a6f6eef6 · schema v1 · pii pii-v1
BSI Financial Services notified customers of a data breach where an unauthorized third party accessed an employee's email account via phishing on June 1, 2017. The attacker used stolen credentials to send emails containing borrower names, addresses, and account numbers. BSI disabled the account, engaged forensic investigators, notified law enforcement, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 1, 2017
Begins
Jun 1, 2017
Discovered
Sep 29, 2017
Filed
vs. sector median
+9 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Oregon State AGbd_9a00a47170115d2e2017-09-29Candidate
- Washington State AGbd_f5d5efd2eaf0fdc22017-09-29Verified
- California State AGbd_e2fbb634a90b77762017-09-27 · +2dVerified
- Massachusetts State AGbd_1d30ef40807cb4f02017-10-04 · +5dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Sep 27 (CA), last Oct 4 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.