ELWYN CALIFORNIA
bd_cc2f42ab3cb4784c · schema v1 · pii pii-v1
Full breach record for ELWYN CALIFORNIA →Elwyn, a Delaware-based organization, disclosed a data event affecting approximately 1,458 Delaware residents. Unauthorized actors accessed employee email accounts between October 9, 2019, and July 21, 2020. The incident involved the exposure of names, Social Security numbers, driver's license numbers, financial account information, and medical information. Elwyn discovered the suspicious activity on June 24, 2020, launched a forensic investigation, reset passwords, and provided one year of credit monitoring via Experian to affected individuals. Written notice was sent on February 11, 2021.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ee540d71ba500a53California State AGfiled 2021-02-11Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/02/Elwyn-Notice-of-Data-Event-Exhibit-1-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2021
- Raw hash
- 15b97ef03773d1c7daeb0773fd96216f0ef8830e965ae9e1c23104a22bb8420d
Reporting entity
- Name
- ELWYN CALIFORNIAnorm: elwyn california
Victim entity
- Name
- ELWYN CALIFORNIAnorm: elwyn california
Incident
- Discovered
- Jun 24, 2020
- Materiality determined
- —
- Notification sent
- Feb 11, 2021
- Affected individuals
- 1,458
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 33 weeks(232 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.