HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighActive
EyeMed Vision Benefits
bd_873b63c5791a9fb8 · schema v1 · pii pii-v1
Full breach record for EyeMed Vision Benefits →EyeMed Vision Care LLC reported an unauthorized access incident occurring between June 24, 2020, and July 1, 2020. The breach affected 54,266 individuals, including 23 Maine residents. Compromised data included names and Social Security Numbers. EyeMed provided two years of complimentary identity monitoring through Kroll, including credit monitoring and fraud consultation. The investigation was ongoing as of the filing date of September 28, 2020.
Maine clockDiscovered Jul 1, 2020 → Filed with AG Sep 28, 202089d ⏱ ME AG >30d13 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1901228616916967California State AGfiled 2020-09-28Verified
- bd_62dc6484cbe942d7Montana State AGfiled 2020-09-28Candidate
- bd_51ab8a9387df3353Oregon State AGfiled 2020-10-12(14d gap)Verified
- bd_5b0c8c38829e67fcWashington State AGfiled 2020-10-12(14d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/596517cc-fc6a-48a5-8470-41f896cc57bc.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 28, 2020
- Raw hash
- a278abf99bfe32317dfdf1f085cba32579075822985bb9900c2289942a113e35
Reporting entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Victim entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Incident
- Discovered
- Jul 1, 2020
- Materiality determined
- —
- Notification sent
- Sep 28, 2020
- Affected individuals
- 54,266
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(89 days from discovery to filing)
- Compliance flags
- ME AG >30d · 89dME resident >60d · 89d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jul 1, 2020→ Filed with AG: Sep 28, 202089d 30 days (soft) ME AG >30d Maine Discovered: Jul 1, 2020→ Notified: Sep 28, 202089d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.