Vertafore
bd_9c928ea0ee207680 · schema v1 · pii pii-v1
Vertafore, a third-party provider of insurance agency management software (QQCatalyst), experienced a configuration error on November 30, 2020, leading to unauthorized public access to reports and forms. The breach potentially exposed names, addresses, birth dates, driver's license numbers, SSNs, and financial account information for customers of Kelly Klee, Inc. Vertafore fixed the error, engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 30, 2020
Discovered
Jul 1, 2021
Filed
vs. sector median
+12 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_caa7b1c2031e35cf2021-07-01Verified
- Indiana State AGbd_ea319c75c84bcffc2021-07-08 · +7dVerified
- Idaho State AGbd_316ff599821890f62021-07-14 · +13dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jul 1 (MA), last Jul 14 (ID) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.