HackingStolen CredentialsTargetedIDENTITY_BASICMediumContained
The Phia Group, LLC
bd_c206b062995998d4 · schema v1 · pii pii-v1
Full breach record for The Phia Group, LLC →The Phia Group, LLC notified South Carolina AG of a data security incident affecting approximately 3,470 individuals. Suspicious activity was discovered on July 9, 2024, involving unauthorized access to personal information (names) between July 8-9, 2024. The company engaged forensic specialists, reported to law enforcement, and provided 12 months of identity monitoring via Kroll.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_f8a3f4c0b2d6866dCalifornia State AGfiled 2026-05-15(5d gap)Verified
- bd_53856ef162652bd8New Hampshire State AGfiled 2026-05-14(6d gap)Verified
- bd_466553d842bc56d4California State AGfiled 2026-01-30(110d gap)Candidate
- bd_ab77d3136d2466cdWashington State AGfiled 2026-01-30(110d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 110d gap
- bd_db0c653aaa12ad94New Hampshire State AGfiled 2026-01-30(110d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2026/Consumer%20Letter%20-%20The%20Phia%20Group.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 20, 2026
- Raw hash
- 20ed7021c7da846641809d095f965e33bd21a009dfcc27c9b371d06c40de923b
Reporting entity
- Name
- The Phia Group, LLCnorm: the phia
Victim entity
- Name
- The Phia Group, LLCnorm: the phia
Incident
- Discovered
- Jul 9, 2024
- Materiality determined
- —
- Notification sent
- Apr 17, 2026
- Affected individuals
- 3,470
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 months(680 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.