MalwareRansomwareCapture Stored DataData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENTMediumContained
ELEVATE SERVICES, INC.
bd_a3856ba06272067d · schema v1 · pii pii-v1
Full breach record for ELEVATE SERVICES, INC. →Elevate Services, Inc. experienced a ransomware attack between March 5 and March 15, 2022. On March 14, 2022, the company discovered that systems were inaccessible due to malicious file encryption. An unknown actor accessed and downloaded files from limited systems. Affected data may include names, addresses, dates of birth, SSNs, driver's license numbers, medical history, and employment information. The company secured systems, notified law enforcement, and offered 12 months of credit monitoring.
Leak gap clock✗ Leak >180d51 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_aa0ea316c8a8bac6Leak Sitecontifiled 2022-04-14(327d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_81a5900cdfa52331Vermont State AGfiled 2023-03-02(5d gap)Verified by operator
- bd_a48b2854bfc15412Montana State AGfiled 2023-02-08(27d gap)Verified by operator
- bd_5ce595d1266de680Montana State AGfiled 2023-04-19(43d gap)Verified by operator
- bd_974c9c80d6c62aebCalifornia State AGfiled 2022-12-28(69d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563989
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 7, 2023
- Raw hash
- 4e6e72721a274543037028cff7b4c16a1883b72d1259879f54040205dae5b010
Reporting entity
- Name
- ELEVATE SERVICES, INC.norm: elevate services
Victim entity
- Name
- ELEVATE SERVICES, INC.norm: elevate services
Incident
- Discovered
- Mar 14, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 51 weeks(358 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.