HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Crum & Forster
bd_8ce7852eedec6c2b · schema v1 · pii pii-v1
Full breach record for Crum & Forster →Crum & Forster reported unauthorized access to its network between December 19, 2021, and March 20, 2022. The incident involved the exfiltration of personal information, including names and Social Security numbers, of current and former employees, insureds, and claimants. The company engaged outside cybersecurity professionals and is offering 12 months of credit monitoring to affected individuals.
Leak gap clock✗ Leak >180d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_c68e486d3bc9c8ceLeak Siteransomhousefiled 2022-12-05(310d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574973
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 11, 2023
- Raw hash
- 95b05f3214d01c8cbe1fab355fbd2303c4da4b296b68b3d297006fb6c1a6e3fc
Reporting entity
- Name
- Crum & Forsternorm: crum forster
Victim entity
- Name
- Crum & Forsternorm: crum forster
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Compliance flags
- Leak >180d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.