HackingSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Kannact
bd_cd661c6340a50480 · schema v1 · pii pii-v1
Full breach record for Kannact →Kannact, Inc. reported a data security incident where an unauthorized user gained access to its system via third-party file transfer software. The breach was discovered on March 13, 2023, with the occurrence date listed as February 6, 2023. Affected data includes protected health information (PHI) and personal information of employees enrolled in health insurance plans through Kannact's partners. Kannact engaged forensic investigators, disabled the compromised software, and is offering credit monitoring and identity theft recovery services to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_07529270f797a54aMaine State AGfiled 2023-09-22Verified
- bd_c082f97720f3e696Oregon State AGfiled 2023-09-22Verified
- bd_2bbf967b1d0ff94cMontana State AGfiled 2023-09-21(1d gap)Candidate
- bd_29de722ce2bf8e1fMontana State AGfiled 2023-10-10(18d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574117
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 15f6cc6ec44fb880099be810eecc79b6f98a9c51f9621650a6fdd7b885d4dd40
Reporting entity
- Name
- Kannactnorm: kannact
- Domain
- kannact.com
Victim entity
- Name
- Kannactnorm: kannact
- Domain
- kannact.com
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via third party file transfer software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 28 weeks(193 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.