Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
CRC Insurance Services, LLC
bd_97f391745ea166b7 · schema v1 · pii pii-v1
Full breach record for CRC Insurance Services, LLC →CRC Insurance Services, LLC reported a security incident on January 18, 2023, where phishing emails led to unauthorized access to a limited number of employee email accounts. The attacker exfiltrated a small percentage of emails. Exposed data may include names, addresses, and other personal information. CRC engaged forensic firms, secured accounts, and is offering Equifax credit monitoring services.
Vermont clock✗ VT AG >45 bday26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_609f8e75669d9e57California State AGfiled 2023-07-26(7d gap)Candidate
- bd_684512eb7188bc5dMontana State AGfiled 2023-07-26(7d gap)Verified
- bd_ef08d8fabbad4f62Idaho State AGfiled 2023-07-26(7d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-19-crc-insurance-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 19, 2023
- Raw hash
- b77a6fc6477c10f4f4760db520f9e32141e1e4ff2a88c63e836b6e554848cb7f
Reporting entity
- Name
- CRC Insurance Services, LLCnorm: crc insurance
Victim entity
- Name
- CRC Insurance Services, LLCnorm: crc insurance
Incident
- Discovered
- Jan 18, 2023
- Materiality determined
- —
- Notification sent
- Jul 19, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 weeks(182 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.