HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
American Armed Forces Mutual Aid Association
bd_bbe179b1d0bcb4d6 · schema v1 · pii pii-v1
Full breach record for American Armed Forces Mutual Aid Association →The American Armed Forces Mutual Aid Association (AAFMAA) notified South Carolina consumers of a cybersecurity incident occurring between January 28-31, 2021. An unauthorized actor accessed AAFMAA systems, viewing/removing files containing names and government IDs. AAFMAA engaged the FBI, secured systems, and offered 24 months of credit monitoring. 242 Rhode Island residents were explicitly identified as affected.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5ad6c774208b6e84Montana State AGfiled 2021-03-05Candidate
- bd_6e8996a917544e20Oregon State AGfiled 2021-03-05Verified
- bd_703e68e362e390c8Washington State AGfiled 2021-03-05Verified
- bd_cd8944e9bf4db0b4California State AGfiled 2021-03-05Verified
Show 1 more filing ↓Show fewer ↑
- bd_dde898c4b50bd37dMaine State AGfiled 2021-03-05Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/AAFMAA.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 5, 2021
- Raw hash
- fa28eff104ef228d6e202a18549613b9fefd10f30e48825efd332c73280039d9
Reporting entity
- Name
- American Armed Forces Mutual Aid Associationnorm: american armed forces mutual aid
Victim entity
- Name
- American Armed Forces Mutual Aid Associationnorm: american armed forces mutual aid
Incident
- Discovered
- Jan 29, 2021
- Materiality determined
- —
- Notification sent
- Mar 5, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation (“FBI”)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.