DisclosureLens
Social EngineeringInformationPhishingStolen CredentialsEmployee Data InvolvedGovernment IDFinancial accountIdentity (basic)MediumContained

EXTREME REACH, INC.

bd_8e0fe881963893cb · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 8, 2017

Filed

Apr 28, 2017

To disclose

11 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

64%
Full breach record for EXTREME REACH, INC.

Extreme Reach, Inc. notified California residents that a phishing email targeted employees on February 8, 2017, resulting in compromised email credentials. The company determined on April 10, 2017, that certain employee email accounts were accessed without authorization. Affected data may include Social Security numbers, driver's license numbers, financial account numbers, credit card numbers, passport numbers, and names. The company engaged forensic investigators and is offering 12 months of credit monitoring through Experian.

California clockDiscovered Feb 8, 2017Notified May 4, 201785d CA 60-day late11 weeks discovery → filing

Incident timeline

discovery → filing · 11 weeks / 79 days

Feb 8, 2017

Begins

Feb 8, 2017

Discovered

Apr 28, 2017

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Massachusetts State AGApr 28 · first
New Hampshire State AGApr 28 · first
California State AGApr 28 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.