Social EngineeringPhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Supplemental Income Trust Fund; MonRoc Administrators LLC
bd_95e1ae162080a30f · schema v1 · pii pii-v1
Full breach record for Supplemental Income Trust Fund; MonRoc Administrators LLC →Supplemental Income Trust Fund notified California residents of a data breach at its third-party administrator, MonRoc Administrators LLC. A phishing attack compromised an administrator email account, granting unauthorized access from March 22 to April 21, 2021. Affected data included names, addresses, dates of birth, Social Security numbers, and account balances. The Plan retained forensic investigators and is offering 24 months of identity monitoring.
California clockDiscovered Mar 22, 2021 → Notified May 1, 202140d ✓ CA 60-day OK10 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_52613eb173f9060bOregon State AGfiled 2021-06-03Verified
- bd_322bbee7734e9c4fMaine State AGfiled 2021-06-01(2d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541552
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 3, 2021
- Raw hash
- ea330ec6e8d399b462a69e95b08217caea4ca5b32c13ba95322e9d1892b9fe2a
Reporting entity
- Name
- Supplemental Income Trust Fundnorm: supplemental income
Victim entity
- Name
- Supplemental Income Trust Fund; MonRoc Administrators LLCnorm: supplemental income trust fund monroc administrators
Incident
- Discovered
- Mar 22, 2021
- Materiality determined
- —
- Notification sent
- May 1, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Third party
- via MonRoc Administrators LLC
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(73 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 40d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 22, 2021→ Notified: May 1, 202140d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.