MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENTMediumContained
ELEVATE SERVICES, INC.
bd_974c9c80d6c62aeb · schema v1 · pii pii-v1
Full breach record for ELEVATE SERVICES, INC. →Elevate Services, Inc. experienced a ransomware attack between March 5 and March 15, 2022, discovered on March 14, 2022. An unknown actor encrypted files and exfiltrated data containing PII, PHI, SSNs, and employment records. The company secured systems, notified law enforcement, and offered credit monitoring.
Leak gap clock✗ Leak >180d41 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_aa0ea316c8a8bac6Leak Sitecontifiled 2022-04-14(258d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_a48b2854bfc15412Montana State AGfiled 2023-02-08(42d gap)Verified by operator
- bd_81a5900cdfa52331Vermont State AGfiled 2023-03-02(64d gap)Verified by operator
- bd_a3856ba06272067dCalifornia State AGfiled 2023-03-07(69d gap)Verified by operator
- bd_5ce595d1266de680Montana State AGfiled 2023-04-19(112d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-560470
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 28, 2022
- Raw hash
- 2dd5e1e8e73649b8f824165e1f18cb82e398c0be00fbadbd8034cf5315e511e9
Reporting entity
- Name
- ELEVATE SERVICES, INC.norm: elevate services
Victim entity
- Name
- ELEVATE SERVICES, INC.norm: elevate services
Incident
- Discovered
- Mar 14, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 41 weeks(289 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.