HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
AMERIFIRST FINANCIAL, INC.
bd_d688caa4c1a25c03 · schema v1 · pii pii-v1
Full breach record for AMERIFIRST FINANCIAL, INC. →AmeriFirst Financial, Inc. disclosed a data breach involving compromised Microsoft Office 365 email accounts. The incident occurred between July 13, 2020, and December 14, 2020, and was discovered on June 18, 2021. Affected data included names, Social Security numbers, bank account numbers, driver's licenses, and passport numbers. The company engaged forensic investigators and offered one year of credit monitoring through Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4b9c647386827a93Montana State AGfiled 2021-06-18Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542030
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2021
- Raw hash
- 59b4adf77f0694599198eb4fa884cc0f45935a2cd3efb57256c6f6de2b868b32
Reporting entity
- Name
- AMERIFIRST FINANCIAL, INC.norm: amerifirst financial
Victim entity
- Name
- AMERIFIRST FINANCIAL, INC.norm: amerifirst financial
Incident
- Discovered
- Jun 18, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.