HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIALMediumContained
The May Institute, Inc.
bd_d04a26b2741bc21c · schema v1 · pii pii-v1
Full breach record for The May Institute, Inc. →The May Institute, Inc. notified the California Attorney General of a data breach where an unauthorized actor potentially accessed or took files on December 5, 2023. The organization became aware of suspicious activity on December 14, 2023. Affected data may include names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical claims information, clinical information, and health insurance information. The company launched an investigation, secured systems, notified law enforcement, and is offering identity theft protection services.
California clockDiscovered Dec 14, 2023 → Notified May 7, 2024145d ✗ CA 60-day late21 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_137142407e3cac51Maine State AGfiled 2024-05-07Verified
- bd_24be293e36e71d44Vermont State AGfiled 2024-05-07Verified
- bd_5207e8054ff815efNew Hampshire State AGfiled 2024-05-07Verified
- bd_266c7d36ba41aac3New Hampshire State AGfiled 2024-04-01(36d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 36d gap
- bd_741bdbdf65f0748bIndiana State AGfiled 2024-04-01(36d gap)Verified
- bd_b84a1b378974faf3Vermont State AGfiled 2024-04-01(36d gap)Verified
- bd_c36bf0a5f4471980Maine State AGfiled 2024-04-01(36d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-584961
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 7, 2024
- Raw hash
- 4b5f7a08752e628093a183a7fb4e5352da046dfe08b6446b930692dbb3613614
Reporting entity
- Name
- The May Institute, Inc.norm: the may institute
Victim entity
- Name
- The May Institute, Inc.norm: the may institute
Incident
- Discovered
- Dec 14, 2023
- Materiality determined
- —
- Notification sent
- May 7, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Provided notice to federal law enforcementProviding notice to state regulators
Compliance
- Time to disclose
- 21 weeks(145 days from discovery to filing)
- Compliance flags
- CA 60-day late · 145d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 14, 2023→ Notified: May 7, 2024145d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.