MalwareRansomwareStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
SafetyCall International
bd_8f0a0432809a2ab2 · schema v1 · pii pii-v1
Full breach record for SafetyCall International →SafetyCall International notified customers of a security incident involving its third-party data hosting provider, Netgain. Netgain experienced a network intrusion starting November 24, 2020, culminating in a ransomware attack on December 3, 2020. Unauthorized access resulted in the potential exfiltration of customer data, including names and product incident reports. SafetyCall engaged outside privacy professionals and confirmed limited personal information was involved. No extensive health records were compromised.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0fcd4f560b8e779fMontana State AGfiled 2021-07-16(3d gap)Candidate
- bd_20a6c843e232f430Montana State AGfiled 2021-08-06(18d gap)Verified
- bd_88c1f5ec83cf3d5fMontana State AGfiled 2021-08-06(18d gap)Verified
- bd_d1fec7b424e0764aCalifornia State AGfiled 2021-08-06(18d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 84d gap
- bd_096bc97d13e4adafCalifornia State AGfiled 2021-08-24(36d gap)Verified
- bd_739b02b3cce842a8Montana State AGfiled 2021-10-11(84d gap)Verified
- bd_ff7e5eba97d29532Montana State AGfiled 2021-10-11(84d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543067
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 19, 2021
- Raw hash
- ecedbeb67017e9e7389f90f886d392b0d8c70af321d08da1b42965fc3f540354
Reporting entity
- Name
- SafetyCall Internationalnorm: safetycall international
Victim entity
- Name
- SafetyCall Internationalnorm: safetycall international
Incident
- Discovered
- Nov 24, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Netgain
- Initial access
- supply_chain
Compliance
- Time to disclose
- 34 weeks(237 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.