DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedTargetedPIIIdentity (basic)LowContained

QBE North America

bd_a2a0fdddd4e3a118 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 21, 2017

Filed

Jan 19, 2018

To disclose

26 weeks

Affected

6state residents only

Confidence

65%
Full breach record for QBE North America5 incidents on file

QBE North America notified Montana residents of a phishing attack on July 19, 2017, which compromised employee email credentials. The attacker accessed mailboxes containing personal data of policyholders. QBE reset passwords, contained the incident, and offered two years of Experian IdentityWorks services to affected individuals.

Incident timeline

undetected · 2 days
discovery → filing · 26 weeks / 182 days

Jul 19, 2017

Begins

Jul 21, 2017

Discovered

Jan 19, 2018

Filed

vs. sector median

+18 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.