MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Landmark Admin
bd_af6fea4c2516a11a · schema v1 · pii pii-v1
Full breach record for Landmark Admin →Landmark Admin, LLC, a third-party administrator for insurance carriers, experienced a data breach from May 13 to June 17, 2024. Unauthorized access resulted in data encryption and exfiltration. Affected data includes names, tax identification numbers, and for some, driver's license, passport, and health information. The company engaged forensic investigators, contained the incident, and implemented extensive remediation measures including MFA and server hardening.
California clockDiscovered May 13, 2024 → Notified Oct 23, 2024163d ✗ CA 60-day late23 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_694502fe4f1453a6Oregon State AGfiled 2024-10-23Verified
- bd_6c7ccc9b72bce270Indiana State AGfiled 2024-10-23Verified
- bd_73af656696be6b73Maine State AGfiled 2024-10-23Candidate
- bd_b9b1aa056e46bc9fWashington State AGfiled 2024-10-23Verified
Show 2 more filings ↓Show fewer ↑
- bd_f2927f007bf0104dDelaware State AGfiled 2024-10-23Verified
- bd_fa4dac0cae950a09Vermont State AGfiled 2024-10-23Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-593796
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 23, 2024
- Raw hash
- 1953afa3dc6c6409ecb0a639a58fd2d30df1de9b28aaa83f58cb3e68ded222c2
Reporting entity
- Name
- Landmark Buildersnorm: landmark builders
- Domain
- landmarkbuilders.com
Victim entity
- Name
- Landmark Adminnorm: landmark admin
Incident
- Discovered
- May 13, 2024
- Materiality determined
- —
- Notification sent
- Oct 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 23 weeks(163 days from discovery to filing)
- Compliance flags
- CA 60-day late · 163d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 13, 2024→ Notified: Oct 23, 2024163d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.