Social EngineeringPhishingBECCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Arroyo Insurance
bd_ab3f9f3371e4b34b · schema v1 · pii pii-v1
Full breach record for Arroyo Insurance →Arroyo Insurance Services, Inc. experienced a business email compromise (BEC) incident. On November 2, 2021, the company became aware of an outgoing spam campaign originating from an employee account. The California Attorney General form lists the breach date as September 2, 2021. An unauthorized party gained access to sensitive personal information, including names, addresses, and potentially Social Security numbers. Arroyo engaged third-party cybersecurity experts, reset passwords, enabled MFA, and offered 12 months of identity theft protection through IDX.
California clockDiscovered Nov 2, 2021 → Notified Apr 27, 2023541d ✗ CA 60-day late18 months discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-566064
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2023
- Raw hash
- 00e3645385f07c8672acbab84ebe19853dd1f8a9f140ac0b89fb210f60e9fbda
Reporting entity
- Name
- Arroyo Insurancenorm: arroyo insurance
- Domain
- arroyoins.com
Victim entity
- Name
- Arroyo Insurancenorm: arroyo insurance
- Domain
- arroyoins.com
Incident
- Discovered
- Nov 2, 2021
- Materiality determined
- —
- Notification sent
- Apr 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Filed breach notification with California Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 months(541 days from discovery to filing)
- Compliance flags
- CA 60-day late · 541d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 2, 2021→ Notified: Apr 27, 2023541d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.