HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
HUB INTERNATIONAL LIMITED
bd_beca12727c6cf68f · schema v1 · pii pii-v1
Full breach record for HUB INTERNATIONAL LIMITED →Hub International Limited identified suspicious activity on January 17, 2023, leading to a forensic investigation that revealed unauthorized access and data exfiltration between December 2022 and January 2023. The attacker used valid credentials to access systems and copy files. Hub isolated systems, engaged forensics, notified law enforcement, and is offering credit monitoring to affected individuals. The incident involved PII, including SSNs and financial account data.
California clockDiscovered Jan 17, 2023 → Notified Aug 11, 2023206d ✗ CA 60-day late29 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_002a2ce297ea740dWashington State AGfiled 2023-08-11Candidate
- bd_5121814598643152New Hampshire State AGfiled 2023-08-11Verified
- bd_8ba4c7ba5b2546f1Montana State AGfiled 2023-08-11Candidate
- bd_ab8a57e9569b7698Oregon State AGfiled 2023-08-11Verified by operator
Show 2 more filings ↓Show fewer ↑
- bd_be646bfc1afb7c83Maine State AGfiled 2023-08-11Verified by operator
- bd_f282f01074b65565Vermont State AGfiled 2023-08-11Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571669
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 11, 2023
- Raw hash
- 7297d40e881109c922af69915d9a725c06de61a92f6afea36bdd42722422868b
Reporting entity
- Name
- HUB INTERNATIONAL LIMITEDnorm: hub international
- Domain
- hubinternational.com
Victim entity
- Name
- HUB INTERNATIONAL LIMITEDnorm: hub international
- Domain
- hubinternational.com
Incident
- Discovered
- Jan 17, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported this event to law enforcement and relevant regulators
Compliance
- Time to disclose
- 29 weeks(206 days from discovery to filing)
- Compliance flags
- CA 60-day late · 206d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 17, 2023→ Notified: Aug 11, 2023206d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.