DisclosureLens
MalwareFinancial ServicesHealthcareFinanceRansomwareData EncryptedRansom DemandedCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountMediumContained

Sequoia Financial Services

bd_c9b6572ad01da3bb · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 2, 2021

Filed

Sep 2, 2021

To disclose

9 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for Sequoia Financial Services

Sequoia Financial Services experienced a ransomware attack between June 28 and July 1, 2021, discovered on July 2, 2021. The attacker encrypted systems and potentially exfiltrated personal information including names, addresses, dates of birth, driver's license numbers, insurance policy numbers, and limited health information. The attack was blocked by anti-malware software, and systems were restored without paying the ransom. The company is offering 24 months of identity monitoring to affected individuals.

California clockDiscovered Jul 2, 2021Notified Aug 30, 202159d CA 60-day OK9 weeks discovery → filing

Incident timeline

undetected · 4 days
discovery → filing · 9 weeks / 62 days

Jun 28, 2021

Begins

Jul 2, 2021

Discovered

Sep 2, 2021

Filed

vs. sector median

on median

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.