Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSMediumContained
Highmark Inc
bd_b2b69efe74984e65 · schema v1 · pii pii-v1
Full breach record for Highmark Inc →Highmark, Inc. disclosed a cybersecurity incident occurring between December 13-15, 2022, where an employee clicked a malicious phishing link, compromising their email account. The threat actor accessed emails containing Protected Health Information (PHI) and PII of Highmark members, including names, SSNs, member IDs, claims data, and financial account numbers. Highmark shut down the mailbox, reset passwords, and implemented network blocking. Affected individuals were offered 24 months of Experian IdentityWorks.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_942a588b7d88d2c3Washington State AGfiled 2023-02-06(4d gap)Verified
- bd_9b2ceab0938674dbDelaware State AGfiled 2023-02-15(5d gap)Verified
- bd_e3ddb304e00287caCalifornia State AGfiled 2023-02-03(7d gap)Candidate
- bd_f75581b2eb9ebe57Maine State AGfiled 2023-02-03(7d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 136d gap
- bd_445a421e449e6ca3New Hampshire State AGfiled 2023-06-26(136d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/04/DE-Highmark.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 10, 2023
- Raw hash
- f511f22f782298798c0bd226f9579c32db5da150605ae72b27bc621d8d8eda0f
Reporting entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Victim entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Incident
- Discovered
- Dec 15, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.