Arroyo Insurance
bd_ab3f9f3371e4b34b · schema v1 · pii pii-v1
Full breach record for Arroyo Insurance →Arroyo Insurance Services, Inc. experienced a business email compromise (BEC) incident. On November 2, 2021, the company became aware of an outgoing spam campaign originating from an employee account. The California Attorney General form lists the breach date as September 2, 2021. An unauthorized party gained access to sensitive personal information, including names, addresses, and potentially Social Security numbers. Arroyo engaged third-party cybersecurity experts, reset passwords, enabled MFA, and offered 12 months of identity theft protection through IDX.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 2, 2021
Begins
Nov 2, 2021
Discovered
Apr 27, 2023
Filed
vs. sector median
+68 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_646ff89a7e821ed82023-04-27Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.