Catholic United Financial
bd_8e14bc0185707723 · schema v1 · pii pii-v1
Full breach record for Catholic United Financial →Catholic United Financial reported a SQL injection attack on its web server. Unauthorized access occurred between November 12, 2016, and August 28, 2017. The company discovered suspicious activity on September 6, 2017. Approximately 127,310 members nationwide had their PII (including SSNs) accessed. 704 Washington residents were affected. The company engaged forensic investigators, notified law enforcement/FBI, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 12, 2016
Begins
Sep 6, 2017
Discovered
Oct 6, 2017
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- California State AGbd_095ea08906d84f192017-10-06Verified
- Montana State AGbd_163b0a2490838b832017-10-06Candidate
- New Hampshire State AGbd_444411c792158acf2017-10-05 · +1dVerified
- Massachusetts State AGbd_d98cc38a86f2cabd2017-10-12 · +6dVerified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- Oregon State AGbd_a56592d36390de292017-10-13 · +7dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Oct 5 (NH), last Oct 13 (OR) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.