Social EngineeringPhishingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
John Stokes Financial
bd_6daf6ca6647619ab · schema v1 · pii pii-v1
Full breach record for John Stokes Financial →John Stokes Financial (JSF) reported a data breach involving unauthorized access to an employee's email account. The incident, discovered on October 14, 2021, involved a phishing attack targeting the employee. Affected data included personal information contained in emails and attachments. JSF secured the account, engaged forensic investigators, and offered one year of complimentary identity monitoring via Kroll to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-550682
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 3, 2022
- Raw hash
- a487e1135cf0c00256d664297a0d031b7a907bf04bbf5a12be3d637c7221aa9e
Reporting entity
- Name
- John Stokes Financialnorm: john stokes financial
- Industry
- financial_services
Victim entity
- Name
- John Stokes Financialnorm: john stokes financial
- Industry
- financial_services
Incident
- Discovered
- Oct 14, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.