Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
SogoTrade, Inc.
bd_91ec508ae185a1a6 · schema v1 · pii pii-v1
Full breach record for SogoTrade, Inc. →SogoTrade, Inc. notified California residents of a data breach involving phishing emails with malicious software that compromised four email accounts between May 8 and May 22, 2024. The incident was discovered on March 18, 2025. Affected data may include names, financial account numbers, Social Security Numbers, and tax identification numbers. The company is providing one year of identity monitoring services through Cyberscout.
California clockDiscovered Mar 18, 2025 → Notified Apr 28, 202541d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_57518a95c288c766Washington State AGfiled 2025-05-07Verified
- bd_7b71ea7e4ce87c5dMaine State AGfiled 2025-05-07Verified
- bd_89435bfbf8a34098New Hampshire State AGfiled 2025-05-07Verified
- bd_af1466bc48c50eadOregon State AGfiled 2025-05-07Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_454759b43703caf2Indiana State AGfiled 2025-05-02(5d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-602415
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 7, 2025
- Raw hash
- e46a2aa5f207a63814f7766fb4b2a77ab5ea5f07cadde01dc51b54e0fa1cc926
Reporting entity
- Name
- SogoTrade, Inc.norm: sogotrade
Victim entity
- Name
- SogoTrade, Inc.norm: sogotrade
Incident
- Discovered
- Mar 18, 2025
- Materiality determined
- —
- Notification sent
- Apr 28, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.001 Spearphishing AttachmentT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_attachment
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 41d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 18, 2025→ Notified: Apr 28, 202541d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.