HackingStolen CredentialsTargetedIDENTITY_BASICPIILowContained
Stretto, Inc.
bd_d220c2724129b6bb · schema v1 · pii pii-v1
Full breach record for Stretto, Inc. →Stretto Inc. notified South Carolina residents of a security incident where an employee account was subject to unauthorized access starting April 17, 2024. Stretto disabled the account, changed the password, and engaged external cybersecurity professionals. Confirmed data accessed included name, address, email, phone, and claim amounts. No SSN/TIN evidence found. No evidence of misuse.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c68b9f29fab17d64Indiana State AGfiled 2024-05-21Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Notice%20-%20Clesius%20and%20Voyager.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 21, 2024
- Raw hash
- feab3f3af6ed0b4ebd81e5702383426083f1fd3dec6aeaea4d5562ecb10ed83b
Reporting entity
- Name
- Stretto, Inc.norm: stretto
- Domain
- cases-cr.stretto-services.com
Victim entity
- Name
- Stretto, Inc.norm: stretto
- Domain
- cases-cr.stretto-services.com
Incident
- Discovered
- Apr 17, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.