HackingStolen CredentialsSpyros PanosData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIHighContained
Gallagher
bd_baf081de7f40be51 · schema v1 · pii pii-v1
Full breach record for Gallagher →Gallagher Bassett Services, Inc. reported a security incident in California involving approximately 1,294 claimants. An individual named Spyros Panos, whose license was revoked, impersonated a licensed physician to conduct unauthorized peer reviews of worker's compensation claims between September 2013 and August 2017. Panos may have viewed names, Social Security numbers, and medical/health insurance information. No evidence of data exfiltration was found. Affected individuals were offered two years of identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,294 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-138559
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 3, 2018
- Raw hash
- 4f3548f8c87867549eb760ea8cf653b20072ce31c0b422cf212250d63a23f43c
Reporting entity
- Name
- Gallagher Bassett Services, Inc.norm: gallagher bassett
Victim entity
- Name
- Gallaghernorm: gallagher
- Domain
- ajg.com
Incident
- Discovered
- Aug 3, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,294
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access· Spyros Panos
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- Spyros PanosExternal
- Initial access
- valid_credentials
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.