HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Beacon Mutual Insurance
bd_9212ea1e5259bdac · schema v1 · pii pii-v1
Full breach record for Beacon Mutual Insurance →The Beacon Mutual Insurance Company notified the California Attorney General of a data security incident. An unauthorized person gained access to systems between January 7 and January 14, 2026, and acquired copies of files. The company detected the activity on January 14, 2026, contained it, and reported it to law enforcement. A review completed on April 16, 2026, determined that certain files contained personal information. The company is offering free identity monitoring services to affected individuals.
California clockDiscovered Jan 14, 2026 → Notified May 18, 2026124d ✗ CA 30-day late18 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_da7048f19e46b32fLeak Siteinc_ransomfiled 2026-01-31(107d gap)Verified by operator
- bd_5b90158bd9f95167Leak Siteinc_ransomfiled 2026-01-14(124d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_96f08282e4c86e4aIndiana State AGfiled 2026-05-18Verified by operator
- bd_e4cb15dcb1bd517cMaine State AGfiled 2026-05-18Verified by operator
- bd_a561b8d222dfacc4Texas State AGfiled 2026-05-19(1d gap)Verified
- bd_5d7dc416180d53c8Massachusetts State AGfiled 2026-05-01(17d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-623604
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2026
- Raw hash
- 8d822b417fbcdcf1a1d8dce033636b91ad80b792fae72882e6e75be4b3e42445
Reporting entity
- Name
- Beacon Mutual Insurancenorm: beacon mutual insurance
- Domain
- beaconmutual.com
Victim entity
- Name
- Beacon Mutual Insurancenorm: beacon mutual insurance
- Domain
- beaconmutual.com
Incident
- Discovered
- Jan 14, 2026
- Materiality determined
- —
- Notification sent
- May 18, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement
Compliance
- Time to disclose
- 18 weeks(124 days from discovery to filing)
- Compliance flags
- CA 30-day late · 124dLeak >90dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 14, 2026→ Notified: May 18, 2026124d 30 calendar days CA 30-day late California Consumers notified: May 18, 2026→ AG copy submitted: May 18, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.