Ursus, Inc.
bd_99a53da8602d20da · schema v1 · pii pii-v1
Full breach record for Ursus, Inc. →Ursus Holdings, LLC experienced a data breach after employees fell victim to a phishing email with a malicious attachment, leading to compromised credentials. The incident involved potential exposure of PII including SSNs, bank account numbers, and driver's license numbers stored in Google Mail and Docs. The company detected suspicious activity on April 25, 2016, and notified affected individuals on September 15, 2016.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 21, 2016
Begins
Apr 25, 2016
Discovered
Sep 19, 2016
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_9d0cf604079ee6db2016-09-15 · +4dCandidate
- Massachusetts State AGbd_9d51c563f8db9ca82016-09-12 · +7dVerified
- New Hampshire State AGbd_16435c4852f6ec482016-09-08 · +11dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Sep 8 (NH), last Sep 19 (CA) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.