MalwareRansomwareLockBit 3.0Data ExfiltratedRansom DemandedData EncryptedCustomer Data InvolvedIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
CVC
bd_83492c31a636df3c · schema v1 · pii pii-v1
Full breach record for CVC →CVC Holding Corp experienced a ransomware attack by the LockBit 3.0 group on November 1, 2023. The attackers may have accessed personal information including Social Security numbers, driver's license numbers, medical information, and health insurance data. The company blocked unauthorized access, engaged cybersecurity experts, and is offering one year of credit monitoring and identity restoration services through Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577602
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2023
- Raw hash
- e801ce95c1a6bd5af752a9bffc765dc38bfeedaf51e4a65a1b7fde0c494d2ae3
Reporting entity
- Name
- CVCnorm: cvc
- Domain
- cvc.com
Victim entity
- Name
- CVCnorm: cvc
- Domain
- cvc.com
Incident
- Discovered
- Nov 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Ransomware· LockBit 3.0
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- LockBit 3.0ExternalFinancial
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.