HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Service Employees International Union
bd_d68395b7ff185d43 · schema v1 · pii pii-v1
Full breach record for Service Employees International Union →Service Employees International Union, Local 32BJ notified Delaware residents that an unauthorized actor accessed its systems between October 21 and November 1, 2021, potentially viewing or acquiring data containing names, Social Security numbers, and financial account numbers. Approximately 1,070 Delaware residents were notified. 32BJ engaged cybersecurity experts, conducted a manual review, and provided 12 months of credit monitoring through Equifax. The incident status is contained.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c4cc74994afa81d8Montana State AGfiled 2022-02-11Candidate
- bd_84e74eed73ac15bfNew Hampshire State AGfiled 2022-02-15(4d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/02/SEIU-Regulator-Notice-Letter-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2022
- Raw hash
- cd4f83020a4c4beaf8b8cfbb9427d9c7d2844189e71bc9ee1bc229c400c311ac
Reporting entity
- Name
- Service Employees International Unionnorm: service employees international union
Victim entity
- Name
- Service Employees International Unionnorm: service employees international union
Incident
- Discovered
- Nov 1, 2021
- Materiality determined
- —
- Notification sent
- Feb 11, 2022
- Affected individuals
- 1,070
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- prompt and continued correspondence with federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.