HackingCustomer Data InvolvedIDENTITY_BASICLowContained
Frax Outsourcing
bd_8967bd1d3f3e8299 · schema v1 · pii pii-v1
Full breach record for Frax Outsourcing →Frax Outsourcing, a subsidiary of TheKey, LLC, experienced a criminal cyberattack between November 2 and November 15, 2022. The threat actor accessed email accounts and a SharePoint drive in a legacy system. The incident potentially exposed personally identifiable information, including names and other data elements, of affected individuals. Frax engaged third-party experts for investigation and has decommissioned the affected legacy environment. Identity theft protection services are being offered to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_313083397f767c1eOregon State AGfiled 2023-10-10Verified
- bd_fcffb72a847f709eMaine State AGfiled 2023-09-22(18d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574914
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 10, 2023
- Raw hash
- 511ecc03ab68b72e566be400794c9bb760306d35d3e4e3d6e9ee146a2e95f387
Reporting entity
- Name
- Frax Outsourcingnorm: frax outsourcing
Victim entity
- Name
- Frax Outsourcingnorm: frax outsourcing
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Sep 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email Collection
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.