Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENTMediumContained
Magnolia
bd_94d17432d5b3a800 · schema v1 · pii pii-v1
Full breach record for Magnolia →Magnolia Health Corporation reported a data breach on February 12, 2016, affecting its employees. On February 3, 2016, an unidentified third party impersonated the CEO via email to obtain a spreadsheet containing employee PII, including SSNs, names, addresses, and financial data. The breach was discovered on February 10, 2016. The company notified law enforcement, filed a notice with the California Attorney General, and offered one year of Experian ProtectMyID services to affected employees.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed100 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60061
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 12, 2016
- Raw hash
- a825ca05f4f239bd9ba6e523d5d44e50484c2a7322625ac3a79ead7faad11522
Reporting entity
- Name
- Magnolianorm: magnolia
- Domain
- magnolia.com
Victim entity
- Name
- Magnolianorm: magnolia
- Domain
- magnolia.com
Incident
- Discovered
- Feb 10, 2016
- Materiality determined
- Feb 12, 2016
- Notification sent
- —
- Affected individuals
- 100
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided a sample copy of this letter to the California Attorney General's office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.