Social EngineeringPhishingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Applied Data Finance, LLC
bd_7ede26d75ea83f94 · schema v1 · pii pii-v1
Full breach record for Applied Data Finance, LLC →Applied Data Finance, LLC d/b/a Personify Financial reported a data breach where an unauthorized third party accessed employee email accounts via spear-phishing. The incident, occurring on July 21, 2018, and discovered November 9, 2018, exposed personal information including names, addresses, SSNs, and account numbers. The company disabled accounts, engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring.
California clockDiscovered Nov 9, 2018 → Notified Nov 9, 20180d ✓ CA 60-day OK12 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_62ac49021db76aa8Montana State AGfiled 2019-01-31(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144350
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2019
- Raw hash
- b9cfdbc61169488ec3546b693ae6e543265653dd21d73c3431f93af8527ee9cd
Reporting entity
- Name
- Applied Data Finance, LLCnorm: applied data finance
Victim entity
- Name
- Applied Data Finance, LLCnorm: applied data finance
Incident
- Discovered
- Nov 9, 2018
- Materiality determined
- —
- Notification sent
- Nov 9, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementNotified appropriate state regulatory authorities
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 9, 2018→ Notified: Nov 9, 20180d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.