Ethos Technologies Inc
bd_71d8bf0ea7b2eb37 · schema v1 · pii pii-v1
Full breach record for Ethos Technologies Inc →Ethos Technologies Inc., an online life insurance provider, discovered on January 12, 2022 that unauthorized actors had exploited a feature in its online insurance application flow to access driver's license numbers. Attackers used pre-obtained personal information (name, DOB, address, license state) to trigger a third-party validation service, then extracted license numbers from website page source code. The unauthorized activity spanned approximately July 15, 2021 through January 12, 2022. Ethos notified federal law enforcement, made technical changes, and engaged a forensic firm.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_454926a96e60de54Maine State AGfiled 2022-02-11Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-550887
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2022
- Raw hash
- 3dbb5c0188667920eb90214277b5bf6e3adc4fe249723bd96fac17af7d76b522
Reporting entity
- Name
- Ethos Technologies Incnorm: ethos technologies
Victim entity
- Name
- Ethos Technologies Incnorm: ethos technologies
- Industry
- Financial ServicesllmTechnologyllm
Incident
- Discovered
- Jan 12, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified California Attorney General per SB-24
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.