Social EngineeringPhishingStolen CredentialsEmployee Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASICMediumContained
EXTREME REACH, INC.
bd_8e0fe881963893cb · schema v1 · pii pii-v1
Full breach record for EXTREME REACH, INC. →Extreme Reach, Inc. notified California residents that a phishing email targeted employees on February 8, 2017, resulting in compromised email credentials. The company determined on April 10, 2017, that certain employee email accounts were accessed without authorization. Affected data may include Social Security numbers, driver's license numbers, financial account numbers, credit card numbers, passport numbers, and names. The company engaged forensic investigators and is offering 12 months of credit monitoring through Experian.
California clockDiscovered Feb 8, 2017 → Notified May 4, 201785d ✗ CA 60-day late11 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-67890
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 28, 2017
- Raw hash
- bd2d0f232506f044bc877d68499d48e13783584d1dda0391cc33911f799fd784
Reporting entity
- Name
- EXTREME REACH, INC.norm: extreme reach
Victim entity
- Name
- EXTREME REACH, INC.norm: extreme reach
Incident
- Discovered
- Feb 8, 2017
- Materiality determined
- —
- Notification sent
- May 4, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notifying state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day late · 85d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 8, 2017→ Notified: May 4, 201785d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.