DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountMediumActive

Gray

bd_c6bd8a5ea2cad3a4 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 17, 2018

Filed

Aug 29, 2018

To disclose

12 days

Affected

1state residents only

Confidence

66%
Full breach record for Gray2 incidents on file

Gray, Inc. notified Montana employees of a phishing incident where an employee's email was compromised starting April 1, 2018. Personal data including names, addresses, SSNs, and banking info were forwarded to an unknown account. Gray engaged Kroll for forensic investigation and provided one year of identity monitoring to affected staff. Investigation was ongoing as of the August 29, 2018 notice.

Incident timeline

undetected · 138 days
discovery → filing · 12 days

Apr 1, 2018

Begins

Aug 17, 2018

Discovered

Aug 29, 2018

Filed

vs. sector median

17 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.