HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICLowContained
American Armed Forces Mutual Aid Association
bd_cd8944e9bf4db0b4 · schema v1 · pii pii-v1
Full breach record for American Armed Forces Mutual Aid Association →The American Armed Forces Mutual Aid Association (AAFMAA) disclosed a data breach occurring between January 28-31, 2021. An unauthorized actor accessed AAFMAA systems and exfiltrated or viewed files containing member names and other personal information. AAFMAA notified the FBI, secured its systems, and offered 24 months of complimentary credit monitoring via Experian to affected individuals. No credit card or financial account data was impacted.
California clockDiscovered Jan 29, 2021 → Notified Mar 5, 202135d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5ad6c774208b6e84Montana State AGfiled 2021-03-05Candidate
- bd_6e8996a917544e20Oregon State AGfiled 2021-03-05Verified
- bd_703e68e362e390c8Washington State AGfiled 2021-03-05Verified
- bd_bbe179b1d0bcb4d6South Carolina State AGfiled 2021-03-05Verified
Show 1 more filing ↓Show fewer ↑
- bd_dde898c4b50bd37dMaine State AGfiled 2021-03-05Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538914
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 5, 2021
- Raw hash
- 31066e86fc5fa419e242a21428116451c3a420af7406a8362fcc969ef76f6d01
Reporting entity
- Name
- American Armed Forces Mutual Aid Associationnorm: american armed forces mutual aid
Victim entity
- Name
- American Armed Forces Mutual Aid Associationnorm: american armed forces mutual aid
Incident
- Discovered
- Jan 29, 2021
- Materiality determined
- —
- Notification sent
- Mar 5, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 35d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 29, 2021→ Notified: Mar 5, 202135d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.