DisclosureLens
HackingProfessional ServicesHealthcareProfessional ServicesStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIdentity (basic)Government IDHealth (basic)MinorMediumContained

Corporate Benefit Marketing, Inc.

bd_b93e90cb889a2827 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 11, 2020

Filed

Aug 19, 2020

To disclose

23 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Corporate Benefit Marketing, Inc.

Corporate Benefit Marketing, Inc. (CBM) disclosed that an unknown actor used stolen credentials to access an employee's email account on March 10-11, 2020. CBM discovered the suspicious activity on March 11, 2020. The breach potentially exposed personal information, including names, addresses, Social Security numbers, and health insurance enrollment details, for individuals and minors. CBM engaged forensic investigators, reset passwords, and offered credit/identity monitoring services.

Incident timeline

undetected · 1 days
discovery → filing · 23 weeks / 161 days

Mar 10, 2020

Begins

Mar 11, 2020

Discovered

Aug 19, 2020

Filed

vs. sector median

+4 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.