Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Highmark Inc
bd_b0ec3199cadaa20c · schema v1 · pii pii-v1
Full breach record for Highmark Inc →Highmark Inc. reported a data breach involving unauthorized access to a MultiPlan employee's email account. The incident, occurring between Dec 23, 2020, and Jan 27, 2021, exposed customer PII including names, SSNs, and financial account numbers. Highmark engaged forensic experts, notified law enforcement, and provided two years of credit monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a365b348cac7fe2bMontana State AGfiled 2021-06-24Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542234
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2021
- Raw hash
- c80946c5c734d54bc7f90257d7abbced9092c33692ab1244b553caecf1006170
Reporting entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Victim entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Incident
- Discovered
- Jan 27, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 weeks(148 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.