HackingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
SmartStart Employment Screening, Inc.
bd_79b8e613fe4dbbff · schema v1 · pii pii-v1
Full breach record for SmartStart Employment Screening, Inc. →SmartStart Employment Screening, Inc. reported an external system breach (hacking) occurring on May 13, 2020, discovered on December 18, 2020. The incident affected 75,103 individuals, including 123 Maine residents. Acquired data included names combined with driver's license numbers. SmartStart notified affected individuals in writing on August 24, 2021, and provided 12 months of identity monitoring services through IDX.
Maine clockDiscovered Dec 18, 2020 → Filed with AG Aug 27, 2021252d ✗ ME AG >90d36 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_050d1847cd215db9California State AGfiled 2021-08-27Verified
- bd_0db3e2cd96640c93South Carolina State AGfiled 2021-08-25(2d gap)Verified
- bd_27e97a822e6e1362Washington State AGfiled 2021-08-24(3d gap)Candidate
- bd_bb3c6553e769b6d4Montana State AGfiled 2021-08-24(3d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a631d297-bcb1-4edc-ad76-cfc3c939fc9c.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2021
- Raw hash
- 9c14db229ac48b6199c736befa9001d669f49ced7700e4940db1407c5bf3e55d
Reporting entity
- Name
- SmartStart Employment Screening, Inc.norm: smartstart employment screening
- Industry
- Professional Services
Victim entity
- Name
- SmartStart Employment Screening, Inc.norm: smartstart employment screening
- Industry
- Professional Services
Incident
- Discovered
- Dec 18, 2020
- Materiality determined
- —
- Notification sent
- Aug 24, 2021
- Affected individuals
- 75,103
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 36 weeks(252 days from discovery to filing)
- Compliance flags
- ME AG >90d · 252dME resident >180d · 249d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 18, 2020→ Filed with AG: Aug 27, 2021252d 90 days ME AG >90d Maine Discovered: Dec 18, 2020→ Notified: Aug 24, 2021249d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.