MalwareRansomwareSupply Chain (3P Vendor)Data EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
BLUE CROSS OF CALIFORNIA
bd_c7a53ca1dcbc2abc · schema v1 · pii pii-v1
Full breach record for BLUE CROSS OF CALIFORNIA →Blue Cross of California reported a ransomware attack on a third-party vendor on August 25, 2021. The incident exposed member PII and PHI, including names, SSNs, Medicare IDs, and bank account details. Blue Cross shut down and rebuilt the affected server and offered one year of Experian IdentityWorks monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-546858
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 26, 2021
- Raw hash
- 0f3a2879307ac0730a61def8e704f0df9f3d99f0f9171c39c731bf6922d88f2e
Reporting entity
- Name
- BLUE CROSS OF CALIFORNIAnorm: blue cross of california
Victim entity
- Name
- BLUE CROSS OF CALIFORNIAnorm: blue cross of california
Incident
- Discovered
- Aug 27, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- A report has been filed with local authorities through the Internet Crime Complaint Center
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.