Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICPIILowResolved
CRC Insurance Services, LLC
bd_d3c3dce79bdf46a6 · schema v1 · pii pii-v1
Full breach record for CRC Insurance Services, LLC →CRC Insurance Services, LLC reported that on January 18, 2023, it determined an unknown third-party gained unauthorized access to a small number of employee email accounts via phishing emails. The breach occurred on January 13, 2023. The actor exfiltrated a small percentage of emails containing personal information such as names and addresses. CRC activated its incident response team, engaged forensic firms, and contained the incident. Credit monitoring is being offered to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6db08079d0fd60adIdaho State AGfiled 2023-12-08Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577671
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2023
- Raw hash
- 9bcc60cf62911ff91ac4f9c3d6c7783c899b1318ef4a6adc59ee4f862e350428
Reporting entity
- Name
- CRC Insurance Services, LLCnorm: crc insurance
Victim entity
- Name
- CRC Insurance Services, LLCnorm: crc insurance
Incident
- Discovered
- Jan 18, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 46 weeks(324 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.