Greylock
bd_c55a125d8e9e0f58 · schema v1 · pii pii-v1
Full breach record for Greylock →Greylock McKinnon Associates, Inc. (GMA), a litigation support consulting firm, detected a cyberattack on May 30, 2023, involving unauthorized access to personal and Medicare information. The incident affected approximately 13,674 individuals, including residents of California, Texas, Puerto Rico, and Rhode Island. Affected data included names, dates of birth, addresses, Medicare Health Insurance Claim Numbers (containing SSNs), and medical/health insurance information. GMA engaged third-party cybersecurity specialists, notified law enforcement and the DOJ, and deleted the affected DOJ data. The company is offering 24 months of credit monitoring and fraud assistance to affected individuals.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_ba7fccfadfcbb07dOregon State AGfiled 2024-04-05Verified by operator
- bd_8b7ba321f28889a0New Hampshire State AGfiled 2024-04-04(1d gap)Verified
- bd_862de986dcc37c52Washington State AGfiled 2024-04-16(11d gap)Verified
- bd_08e358e2c4d44d73Montana State AGfiled 2024-02-23(42d gap)Candidate
Show 3 more filings ↓Show fewer ↑up to 42d gap
- bd_8b8abd614469d3d9New Hampshire State AGfiled 2024-02-23(42d gap)Verified
- bd_e0ca51cf3adad76cMaine State AGfiled 2024-02-23(42d gap)Verified
- bd_ebe27468fd5864a1Indiana State AGfiled 2024-02-23(42d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583540
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2024
- Raw hash
- e261002fb5c623af008657fd586b8de61e69607438e55854cc3b72de2921b34f
Reporting entity
- Name
- Greylocknorm: greylock
- Domain
- gma-us.com
Victim entity
- Name
- Greylocknorm: greylock
- Domain
- gma-us.com
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Apr 8, 2024
- Affected individuals
- 13,674
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the U.S. Department of Justice (DOJ)Notified law enforcement
Compliance
- Time to disclose
- 44 weeks(311 days from discovery to filing)
- Compliance flags
- CA 60-day late · 314d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 30, 2023→ Notified: Apr 8, 2024314d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.