Lamps Plus, Inc.
bd_8f11e2addafc4d7b · schema v1 · pii pii-v1
Full breach record for Lamps Plus, Inc. →On February 11, 2016, an unknown criminal sent a phishing email to a Lamps Plus employee, redirecting the response to the attacker. This resulted in the exfiltration of W-2 data for all 2015 employees, including names, addresses, Social Security numbers, and earnings. The breach was discovered on March 2, 2016, when employees reported fraudulent tax returns filed in their names. The data was used for tax-related identity theft and refund fraud. Lamps Plus notified law enforcement, the California AG, and affected employees, and provided one year of identity monitoring services via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 11, 2016
Begins
Mar 2, 2016
Discovered
Mar 23, 2016
Filed
vs. sector median
5 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.