Genex Services, LLC
bd_b44cde439e08d4f8 · schema v1 · pii pii-v1
Full breach record for Genex Services, LLC →Genex Services, LLC, a managed care service provider, experienced a data security incident resulting from a phishing attack that compromised two employee laptops. The company became aware of suspicious activity on February 25, 2025. The California Attorney General lists the breach date as January 22, 2025. Personal information, including names and other data elements, was potentially accessed by an unauthorized threat actor. Genex activated its incident response plan, notified the FBI, engaged third-party cybersecurity experts, and is offering 24 months of identity monitoring via Kroll to affected individuals.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_6e7b15e133927c7eIndiana State AGfiled 2025-07-09Verified
- bd_8a7a15ccb343c3bdNew Hampshire State AGfiled 2025-07-09Verified
- bd_5754f2b8af0cb57bTexas State AGfiled 2025-07-10(1d gap)Candidate
- bd_67a39fbd2dc3f748Vermont State AGfiled 2025-07-10(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_e6724d8301e225b9Maine State AGfiled 2025-07-10(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605206
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 9, 2025
- Raw hash
- c1a8d6e30e5ea0e9e49822bea44953fca5524d690b38ff20d95c22ea11947afd
Reporting entity
- Name
- Genex Services, LLCnorm: genex services
Victim entity
- Name
- Genex Services, LLCnorm: genex services
Incident
- Discovered
- Feb 25, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 Phishing
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(134 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.