DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingBECCustomer Data InvolvedDelayed DiscoveryPIIIdentity (basic)Government IDMediumContained

Arroyo Insurance

bd_ab3f9f3371e4b34b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 2, 2021

Filed

Apr 27, 2023

To disclose

18 months

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for Arroyo Insurance

Arroyo Insurance Services, Inc. experienced a business email compromise (BEC) incident. On November 2, 2021, the company became aware of an outgoing spam campaign originating from an employee account. The California Attorney General form lists the breach date as September 2, 2021. An unauthorized party gained access to sensitive personal information, including names, addresses, and potentially Social Security numbers. Arroyo engaged third-party cybersecurity experts, reset passwords, enabled MFA, and offered 12 months of identity theft protection through IDX.

California clockDiscovered Nov 2, 2021Notified Apr 27, 2023541d CA 60-day late18 months discovery → filing

Incident timeline

undetected · 61 days
discovery → filing · 18 months / 541 days

Sep 2, 2021

Begins

Nov 2, 2021

Discovered

Apr 27, 2023

Filed

vs. sector median

+68 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGApr 27 · first
California State AGApr 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.