AccidentalMisconfigurationCustomer Data InvolvedPIIIDENTITY_BASICHEALTH_BASICLowContained
WCF NATIONAL INSURANCE COMPANY
bd_8824d08668bc001b · schema v1 · pii pii-v1
Full breach record for WCF NATIONAL INSURANCE COMPANY →WCF National Insurance Company experienced a data security breach between June 23, 2022, and September 20, 2022. A website misconfiguration allowed unauthorized users to access workers' compensation claims data, including names and generalized medical information. No Social Security numbers or financial information were compromised. The company corrected the misconfiguration and restricted access upon discovery.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fadea92271e97b4aOregon State AGfiled 2022-10-25Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-558582
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2022
- Raw hash
- e45bb0f312cad700692eea70b7de2fe6441515e4e881e928205c32c673ff6af9
Reporting entity
- Name
- WCF NATIONAL INSURANCE COMPANYnorm: wcf national insurance
- Industry
- financial_services
Victim entity
- Name
- WCF NATIONAL INSURANCE COMPANYnorm: wcf national insurance
- Industry
- financial_services
Incident
- Discovered
- Sep 20, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.