HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Self Insured Plans, LLC
bd_d3a948c6afb51a5c · schema v1 · pii pii-v1
Full breach record for Self Insured Plans, LLC →90 Degree Benefits Wisconsin (formerly EBSO, Inc.) notified affected individuals of a data security incident occurring on February 27, 2022. Unauthorized access to systems containing personal information was confirmed, though it was undetermined if specific individual data was viewed. The company engaged independent digital forensics, notified the FBI, and implemented enhanced security measures. Affected individuals were offered complimentary identity monitoring and protection services through IDX.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_a69585f431ff6887Delaware State AGfiled 2022-06-09(49d gap)Verified
- bd_a6e44b8edc707de0South Carolina State AGfiled 2022-06-09(49d gap)Verified
- bd_cafd8c7f6de047f6HHS OCRfiled 2022-06-09(49d gap)Verified
- bd_25a5bc689821eccdMaine State AGfiled 2022-06-10(50d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 88d gap
- bd_55f88b2fe516be05California State AGfiled 2022-06-10(50d gap)Verified
- bd_b3b3f35907927dbdOregon State AGfiled 2022-06-10(50d gap)Verified
- bd_04696d915e686bf7Montana State AGfiled 2022-07-18(88d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/06/Pages-from-90-Degree-Benefits-Delaware-AG-002.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2022
- Raw hash
- e3fa3ec085fd48031b84fd48c8803bf4e89e9555d9cd0594d1e447ced4016451
Reporting entity
- Name
- 90 Degree Benefits Wisconsinnorm: 90 degree benefits wisconsin
Victim entity
- Name
- Self Insured Plans, LLCnorm: self insured plans
Incident
- Discovered
- Feb 27, 2022
- Materiality determined
- —
- Notification sent
- Jun 9, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.