DisclosureLens
MalwareTechnologyProfessional ServicesInformationRansomwareData EncryptedEmployee Data InvolvedIdentity (basic)Government IDEmploymentMediumContained

Collabera

bd_b7536fb665576b4c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 8, 2020

Filed

Jul 21, 2020

To disclose

6 weeks

Affected

Not disclosed

Linked

9 filings

Confidence

64%
Full breach record for Collabera

Collabera, Inc. experienced a ransomware attack on its network system. On June 8, 2020, the company identified malware consistent with ransomware and restored data from backups. On June 10, 2020, it became aware that an unauthorized party had obtained some employee data. The incident likely involved employee personal information, including names, addresses, phone numbers, Social Security Numbers, dates of birth, benefits info, passport/visa info, and email addresses. Collabera engaged forensic experts and law enforcement, and is offering two years of complimentary credit monitoring through Experian.

Leak gap clock Leak >30d6 weeks discovery → filing

Incident timeline

undetected · 15 days
discovery → filing · 6 weeks / 43 days

May 24, 2020

Begins

Jun 8, 2020

Discovered

Jul 21, 2020

Filed

vs. sector median

13 wks faster

This filing is one of 9 about the same incident.View merged incident
A leak claim by maze about this victim predates this filing by 43 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 12d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Jul 9 (WA), last Jul 21 (CA) — a 12-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.