HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
STATE AUTOMOBILE MUTUAL INSURANCE COMPANY
bd_bcf0a02dc0fed2cc · schema v1 · pii pii-v1
Full breach record for STATE AUTOMOBILE MUTUAL INSURANCE COMPANY →State Automobile Mutual Insurance Company reported a data breach occurring between March 11 and March 31, 2021. An unknown actor exploited an insurance quote application's prefill feature to access personal information, including names, driver's license numbers, and dates of birth, of prospective customers with whom the company had no prior relationship. The company engaged a cybersecurity firm, notified law enforcement, and provided one year of complimentary identity monitoring through Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540747
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2021
- Raw hash
- c2289527e8a9d08d9ee31249d271b703e50e40b6996572d1b5669cc154d945d7
Reporting entity
- Name
- STATE AUTOMOBILE MUTUAL INSURANCE COMPANYnorm: state automobile mutual insurance
Victim entity
- Name
- STATE AUTOMOBILE MUTUAL INSURANCE COMPANYnorm: state automobile mutual insurance
Incident
- Discovered
- Mar 31, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.