Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CPT Group, Inc.
bd_9d154eb6b5f6bc2e · schema v1 · pii pii-v1
Full breach record for CPT Group, Inc. →CPT Group, Inc. notified Delaware residents of a phishing incident where an unauthorized individual accessed an employee's email account from Nov 22 to Dec 8, 2017. The breach potentially exposed class member names, addresses, and Social Security Numbers. CPT engaged forensic investigators, implemented multi-factor authentication, and offered one year of Kroll Identity Monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c31e9c4116a19590Montana State AGfiled 2018-05-08Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2018/06/CPT-Group-Sample-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2018
- Raw hash
- 57652acf49ea910b9a060b8ab385bb63391f9ce9ddfa611282c051b74ed65f57
Reporting entity
- Name
- CPT Group, Inc.norm: cpt group
Victim entity
- Name
- CPT Group, Inc.norm: cpt group
Incident
- Discovered
- Feb 8, 2018
- Materiality determined
- —
- Notification sent
- May 9, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 weeks(89 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.