MalwarePhishingRansomwareData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
Magellan Health
bd_ab19fc861c82e826 · schema v1 · pii pii-v1
Full breach record for Magellan Health →Magellan Health, Inc. disclosed a ransomware attack discovered on April 11, 2020, following a phishing email on April 6, 2020. The attacker exfiltrated personal information including names, addresses, SSNs, and tax details from a corporate server before deploying ransomware. Magellan engaged Mandiant for forensics, notified the FBI, and offered three years of Experian IdentityWorks to affected individuals.
California clockDiscovered Apr 11, 2020 → Notified May 12, 202031d ✓ CA 60-day OK4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_5bd5952fe83a4024Oregon State AGfiled 2020-05-11Candidate
- bd_ae473065eafe4312Montana State AGfiled 2020-05-11Verified
- bd_c7cf9063b0b75322Washington State AGfiled 2020-05-11Verified
- bd_9e737f4798eb5a36South Carolina State AGfiled 2020-05-12(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 32d gap
- bd_34de5bda8012b71cCalifornia State AGfiled 2020-06-12(32d gap)Verified
- bd_8bced8d5ed3979b9HHS OCRfiled 2020-06-12(32d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-189886
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2020
- Raw hash
- a88c34d54be1eb3e6deef4d74cdaf6ff19669d44d2c6ddc96e2e9f09ddd8759a
Reporting entity
- Name
- Magellan Healthnorm: magellan health
- Domain
- magellanhealth.com
Victim entity
- Name
- Magellan Healthnorm: magellan health
- Domain
- magellanhealth.com
Incident
- Discovered
- Apr 11, 2020
- Materiality determined
- —
- Notification sent
- May 12, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to, and is working closely with, the appropriate law enforcement authorities, including the FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 31d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 11, 2020→ Notified: May 12, 202031d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.