HackingData ExfiltratedEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALEMPLOYMENTEDUCATIONMediumContained
The Metropolitan Companies, Inc.
bd_a9ad642dd08fdfe7 · schema v1 · pii pii-v1
Full breach record for The Metropolitan Companies, Inc. →The Metropolitan Companies, Inc. disclosed that an unauthorized third party accessed its computer systems on April 21, 2014, potentially removing documents containing personal information. Affected data includes names, addresses, SSNs, dates of birth, education/work history, and financial information. The company removed system access, engaged forensic experts, and offered one year of identity theft protection via Kroll. Remediation included enhanced firewall protections and threat detection.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-45526
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2014
- Raw hash
- 51979b0433e0eb26d72125827944daf60dc63ff7aa13ebd89dc5da2baa7b7ee3
Reporting entity
- Name
- Metropolitannorm: metropolitan
- Domain
- metropolitanclt.com
Victim entity
- Name
- The Metropolitan Companies, Inc.norm: the metropolitan companies
Incident
- Discovered
- Apr 21, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALEMPLOYMENTEDUCATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.