DisclosureLens
Social EngineeringTechnologyInformationPhishingEmployee Data InvolvedIdentity (basic)Government IDEmploymentMediumContained

Aspiranet

bd_922e45aa4f2f6d88 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 21, 2016

Filed

Mar 25, 2016

To disclose

4 days

Affected

Not disclosed

Confidence

64%
Full breach record for Aspiranet

On March 21, 2016, Aspiranet was targeted by an email spoofing scam. The incident resulted in the inadvertent disclosure of W-2 information (name, address, SSN) for current and former employees to a third party. Aspiranet detected the incident within 30 minutes, confirmed it was isolated, and offered two years of identity protection. Remediation includes policy reviews and employee training.

California clockDiscovered Mar 21, 2016Notified Mar 28, 20167d CA 60-day OK4 days discovery → filing

Incident timeline

discovery → filing · 4 days

Mar 21, 2016

Begins

Mar 21, 2016

Discovered

Mar 25, 2016

Filed

vs. sector median

18 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.