The Affiliated Group
bd_d7bfbdef63373e43 · schema v1 · pii pii-v1
Full breach record for The Affiliated Group →The Affiliated Group (TAG) confirmed on March 28, 2018, that an unauthorized actor gained access to one employee email account following a phishing incident in November 2017. The attacker used the account to send phishing emails. A review determined that names, Social Security numbers, medical record numbers, limited treatment information, subscriber IDs, and some financial account information were potentially accessible. 1,289 California residents were notified starting September 19, 2018. TAG provided 12 months of identity theft protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 1, 2017
Begins
Mar 28, 2018
Discovered
Sep 19, 2018
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_d8c2bc646745bfb92018-09-19Verified
- Montana State AGbd_a54d25ade4e6dc582018-09-18 · +1dCandidate
- New Hampshire State AGbd_e1d6c24523b7f8412018-09-27 · +8dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Sep 18 (MT), last Sep 27 (NH) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.