Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Applied Plan Administrators ("APA"), a division of The Retirement Advantage, Inc. ("TRA")
bd_b3b1a82358873d33 · schema v1 · pii pii-v1
Full breach record for Applied Plan Administrators ("APA"), a division of The Retirement Advantage, Inc. ("TRA") →The Retirement Advantage, Inc. (TRA) reported a data incident involving its division, Applied Plan Administrators (APA). A phishing attack resulted in unauthorized access to a single APA email account from February 10-12, 2018. The account contained personal information including names, addresses, Social Security numbers, and financial account numbers. TRA secured the account, engaged forensic investigators, and offered 12 months of free credit monitoring to affected California residents.
California clockDiscovered Feb 12, 2018 → Notified Mar 29, 201845d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134841
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 28, 2018
- Raw hash
- e3d5d524b35ca734bdf22cbe1fb6ecbd885ed7c89381233700866044932f3884
Reporting entity
- Name
- THE RETIREMENT ADVANTAGE, INC.norm: the retirement advantage
Victim entity
- Name
- Applied Plan Administrators ("APA"), a division of The Retirement Advantage, Inc. ("TRA")norm: applied plan administrators apa a division of the retirement advantage inc tra
Incident
- Discovered
- Feb 12, 2018
- Materiality determined
- —
- Notification sent
- Mar 29, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Submitted Data Incident Notification to California Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 45d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 12, 2018→ Notified: Mar 29, 201845d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.