HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Symphonix
bd_b27aaea900f94158 · schema v1 · pii pii-v1
Full breach record for Symphonix →Symphonix Health, a healthcare services provider, reported a cybersecurity incident involving its third-party vendor, Newkirk Products, Inc. On May 21, 2016, unauthorized access occurred to a server containing member information. The breach exposed names, addresses, dates of birth, and plan details, but explicitly excluded SSNs, banking info, or medical records. Newkirk shut down the server, engaged forensic investigators, and notified law enforcement. Affected members were offered two years of identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63451
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 19, 2016
- Raw hash
- 856f317dac03f007d0a4c062017e360bbe68a56f25c197a485e9f6d3e22ef03e
Reporting entity
- Name
- NEWKIRK Oklahomanorm: newkirk oklahoma
- Domain
- newkirkoklahoma.com
Victim entity
- Name
- Symphonixnorm: symphonix
- Domain
- symphonix.com
Incident
- Discovered
- Jul 6, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.