Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Legacy Post Acute Care
bd_b698aab289270d43 · schema v1 · pii pii-v1
Full breach record for Legacy Post Acute Care →Legacy Post Acute Care reported a security incident where unauthorized users accessed multiple employee email accounts between January 19, 2022, and March 2, 2022. The breach exposed personal information, including names, of individuals whose data was contained in the affected emails. The company secured the accounts, engaged outside cybersecurity professionals for forensic investigation, and offered one year of complimentary credit monitoring via Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-558178
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 12, 2022
- Raw hash
- 8bc99f6faec1a275dee6fe1b53c1cb409c838a7125db983ee05fa4f66f0d76d2
Reporting entity
- Name
- Legacy Post Acute Carenorm: legacy post acute care
Victim entity
- Name
- Legacy Post Acute Carenorm: legacy post acute care
Incident
- Discovered
- Sep 12, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.