Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Baja Bound Insurance Services
bd_752aecff8cdf0028 · schema v1 · pii pii-v1
Full breach record for Baja Bound Insurance Services →Baja Bound Insurance Services, Inc. discovered on December 16, 2015, that an agent's email account may have been compromised via a phishing attack. The incident potentially exposed personal information including names, addresses, dates of birth, driver's license numbers, and credit card numbers. Social Security numbers were not involved. The company offered one year of identity monitoring through Kroll and implemented two-factor authentication for email accounts as remediation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60000
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 8, 2016
- Raw hash
- 3d9d4b84886ffedf1e96b5a0fe2f800a3d3032ecb3b26d0cde33e0952c765471
Reporting entity
- Name
- Baja Bound Insurance Servicesnorm: baja bound insurance
- Domain
- bajabound.com
Victim entity
- Name
- Baja Bound Insurance Servicesnorm: baja bound insurance
- Domain
- bajabound.com
Incident
- Discovered
- Dec 16, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.