HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMINORMediumContained
Corporate Benefit Marketing, Inc.
bd_b93e90cb889a2827 · schema v1 · pii pii-v1
Full breach record for Corporate Benefit Marketing, Inc. →Corporate Benefit Marketing, Inc. (CBM) reported unauthorized access to an employee email account on March 10-11, 2020, via stolen credentials. The breach potentially exposed personal information of individuals enrolled in health insurance plans, including minors. CBM reset passwords, engaged forensic investigators, and offered credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193251
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 19, 2020
- Raw hash
- e6ab6baddbe0169ef7c141633835ef8c6c866de3c897d7e3b4ffaf869bcad26f
Reporting entity
- Name
- Patriot Growth Insurance Services, LLCnorm: patriot growth insurance
Victim entity
- Name
- Corporate Benefit Marketing, Inc.norm: corporate benefit marketing
Incident
- Discovered
- Mar 11, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- notifying state and federal regulators, as required
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(161 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.