Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Ursus, Inc.
bd_99a53da8602d20da · schema v1 · pii pii-v1
Full breach record for Ursus, Inc. →Ursus Holdings, LLC reported a data breach affecting employee email accounts. An employee received a phishing email with a malicious PDF attachment, providing credentials to the attacker. The attacker used these credentials to send blast emails to contacts. The breach potentially exposed PII including SSNs, bank account numbers, driver's license numbers, and credit card numbers stored in Google Mail/Docs. Ursus provided 12 months of identity repair and credit monitoring via AllClear ID.
California clockDiscovered Apr 25, 2016 → Notified Sep 15, 2016143d ✗ CA 60-day late21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9d0cf604079ee6dbMontana State AGfiled 2016-09-15(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63932
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 19, 2016
- Raw hash
- 65eba1ffe62d7ae1c1a88ae495e8f8a39589f2f1ae810de8df84e4b9931864ae
Reporting entity
- Name
- Ursus, Inc.norm: ursus
- Domain
- ursusinc.com
Victim entity
- Name
- Ursus, Inc.norm: ursus
- Domain
- ursusinc.com
Incident
- Discovered
- Apr 25, 2016
- Materiality determined
- —
- Notification sent
- Sep 15, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 weeks(147 days from discovery to filing)
- Compliance flags
- CA 60-day late · 143d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 25, 2016→ Notified: Sep 15, 2016143d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.