Social EngineeringTechnologyProfessional ServicesInformationPhishingStolen CredentialsSupply Chain (3P Vendor)Multi-Stage ChainCustomer Data InvolvedData ExfiltratedPIIIDENTITY_BASICLowContained
Willis Towers Watson
bd_7ffaa3ea89dea9b8 · schema v1 · pii pii-v1
On February 21, 2018, Willis Towers Watson (WTW), a vendor of Amgen Inc., suffered a phishing incident that led to unauthorized access to personal information. The data involved included names, addresses, phone numbers, and claim/injury descriptions of individuals involved in civil litigation and workers' compensation claims against Amgen. WTW engaged a cybersecurity firm to investigate, activated security protocols, and offered affected individuals complimentary TransUnion credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-137458
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2018
- Raw hash
- 79b21f923cc739e0c721721a0529d48ca2c4c3fb2d7931210c92a7e2d29db551
Reporting entity
- Name
- AMGEN INC.norm: amgen
Victim entity
- Name
- Willis Towers Watsonnorm: willis towers watson
- Industry
- TechnologyllmProfessional Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Third party
- via Willis Towers Watson
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.