Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
American Federation of Musicians and Employers' Pension Fund
bd_bbbbe1f72be2995a · schema v1 · pii pii-v1
Full breach record for American Federation of Musicians and Employers' Pension Fund →The American Federation of Musicians and Employers' Pension Fund reported a cybersecurity incident occurring on May 22, 2020, discovered on August 18, 2020. The breach involved phishing and unauthorized access resulting in the compromise of names and Social Security Numbers for 3,439 individuals, including 3 Maine residents. Notification was sent on January 11, 2021, offering 12 months of credit monitoring and identity restoration services via TransUnion.
Maine clockDiscovered Aug 18, 2020 → Filed with AG Jan 12, 2021147d ✗ ME AG >90d21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a73db7963aed25bbMaine State AGfiled 2021-01-12Verified
- bd_1de5f609fa8e90b7Montana State AGfiled 2021-01-11(1d gap)Candidate
- bd_ed0f72b54a8ca9e1California State AGfiled 2021-01-11(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/12168c6c-e827-44c9-b8a0-9cd269f3606b.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2021
- Raw hash
- 917d5631deef92176c9f22019143fc1cb02de95d98813de5fd8932e3b0b50a0e
Reporting entity
- Name
- American Federation of Musicians and Employers' Pension Fundnorm: american federation of musicians and employers pension
Victim entity
- Name
- American Federation of Musicians and Employers' Pension Fundnorm: american federation of musicians and employers pension
Incident
- Discovered
- Aug 18, 2020
- Materiality determined
- —
- Notification sent
- Jan 11, 2021
- Affected individuals
- 3,439
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 weeks(147 days from discovery to filing)
- Compliance flags
- ME AG >90d · 147dME resident >60d · 146d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 18, 2020→ Filed with AG: Jan 12, 2021147d 90 days ME AG >90d Maine Discovered: Aug 18, 2020→ Notified: Jan 11, 2021146d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.