DisclosureLens
Social EngineeringRetail & ConsumerRetailPhishingBECData ExfiltratedEmployee Data InvolvedWire FraudGovernment IDIdentity (basic)Financial accountEmploymentMediumContained

Lamps Plus, Inc.

bd_8f11e2addafc4d7b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 2, 2016

Filed

Mar 23, 2016

To disclose

21 days

Affected

Not disclosed

Confidence

65%
Full breach record for Lamps Plus, Inc.

On February 11, 2016, an unknown criminal sent a phishing email to a Lamps Plus employee, redirecting the response to the attacker. This resulted in the exfiltration of W-2 data for all 2015 employees, including names, addresses, Social Security numbers, and earnings. The breach was discovered on March 2, 2016, when employees reported fraudulent tax returns filed in their names. The data was used for tax-related identity theft and refund fraud. Lamps Plus notified law enforcement, the California AG, and affected employees, and provided one year of identity monitoring services via Kroll.

California clockDiscovered Mar 2, 2016Notified Mar 3, 20161d CA 60-day OK21 days discovery → filing

Incident timeline

undetected · 20 days
discovery → filing · 21 days

Feb 11, 2016

Begins

Mar 2, 2016

Discovered

Mar 23, 2016

Filed

vs. sector median

5 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.