Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedPIIIDENTITY_BASICLowContained
Everest Global Services, Inc
bd_cff0a20abebecd51 · schema v1 · pii pii-v1
Full breach record for Everest Global Services, Inc →Everest Global Services, Inc. reported unauthorized access to five email accounts between August 8-16, 2022, following suspicious activity detected on August 15, 2022. The incident involved phishing leading to credential compromise and email collection. Personal information of customers was present in compromised accounts. Everest engaged forensic experts, secured the environment, reset passwords, enforced MFA, and offered IDX identity protection services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1e1cd906474ea4caCalifornia State AGfiled 2023-07-27(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/everest-global-20230728.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- bdd22bacf4350a167a4358b38411f3101fd5ca14e48aa1e2f8715c8a7c5c2e52
Reporting entity
- Name
- Everest Global Services, Incnorm: everest global
Victim entity
- Name
- Everest Global Services, Incnorm: everest global
Incident
- Discovered
- Aug 15, 2022
- Materiality determined
- —
- Notification sent
- Jul 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 50 weeks(347 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.