MalwareFinancial ServicesFinanceRansomwareCapture Stored DataRansom DemandedData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedData EncryptedPIILowContained
ALVARIA, INC.
bd_a4e87f4bc8c1de69 · schema v1 · pii pii-v1
Full breach record for ALVARIA, INC. →On March 9, 2023, Alvaria, Inc., a workforce management and call center technology company, suffered a ransomware attack on a portion of its customer environment. The attacker obtained and exfiltrated data associated with Populus Financial Group customers. Alvaria secured networks, restored systems via backups, engaged forensic experts, and notified the FBI. Affected individuals were offered 24 months of Experian credit monitoring.
Leak gap clock⏱ Leak >90d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 11 about the same incident.View merged incident
A leak claim by hive about this victim predates this filing by 152 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_0f1c1d4399267551HHS OCRfiled 2023-05-26(3d gap)Verified
- bd_2b6b416f814bf327HHS OCRfiled 2023-05-26(3d gap)Verified
- bd_35a0583bd128af1dHHS OCRfiled 2023-05-26(3d gap)Verified
- bd_829fa9177a1f7e4fHHS OCRfiled 2023-05-26(3d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 3d gap
- bd_86fab8777f09847aHHS OCRfiled 2023-05-26(3d gap)Verified
- bd_91ad84e8924f7ed1HHS OCRfiled 2023-05-26(3d gap)Verified
- bd_9384d7d17885ad15HHS OCRfiled 2023-05-26(3d gap)Verified
- bd_ab2b25d3361ed4acHHS OCRfiled 2023-05-26(3d gap)Verified
- bd_aefa377a9796e6a8California State AGfiled 2023-05-26(3d gap)Verified
- bd_d557ad3b003f6a7dHHS OCRfiled 2023-05-26(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567145
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2023
- Raw hash
- c973327238154ac546d35132b9dcb9303a584aaccddb8fe30b0eb1dfd84df6dd
Reporting entity
- Name
- Populus Financial Group, Inc.norm: populus financial
Victim entity
- Name
- ALVARIA, INC.norm: alvaria
- Domain
- alvaria.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 23, 2023
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)
- Third party
- via Alvaria, Inc.
Compliance
- Compliance flags
- Leak >90d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.