Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Steel Partners Holdings L.P.
bd_88361305fd97eb21 · schema v1 · pii pii-v1
Full breach record for Steel Partners Holdings L.P. →Steel Partners Holdings LP notified South Carolina residents of a data breach involving unauthorized access to an employee's email account. The incident, discovered in May 2020, exposed personal information including names, Social Security numbers, dates of birth, and health information related to disability or workers' compensation claims. Steel Partners locked the account, engaged forensic investigators, reset passwords, and implemented stricter multi-factor authentication. Affected individuals were offered two years of credit monitoring via Experian IdentityWorks.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_6be8759b2eb0d348Montana State AGfiled 2020-06-29Candidate
- bd_d8b05cdca0e42362Delaware State AGfiled 2020-06-29Verified
- bd_d278d119b9afcdc0California State AGfiled 2020-07-16(17d gap)Candidate
- bd_3ca7167cc02cf496California State AGfiled 2020-08-02(34d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2020/SteelPartners.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2020
- Raw hash
- 623dbb634cb0445d381da53832077b1147f88383d5698f1175476aa2f82a23a0
Reporting entity
- Name
- Steel Partners Holdings L.P.norm: steel partners
Victim entity
- Name
- Steel Partners Holdings L.P.norm: steel partners
Incident
- Discovered
- May 29, 2020
- Materiality determined
- —
- Notification sent
- Jun 29, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.