MisusePrivilege AbuseStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
PROGRESSIVE CASUALTY INSURANCE COMPANY
bd_daa70fe37b441c8f · schema v1 · pii pii-v1
Full breach record for PROGRESSIVE CASUALTY INSURANCE COMPANY →Progressive Casualty Insurance Company notified California residents that a third-party call center provider's employees improperly shared Progressive access credentials with unauthorized individuals. This occurred on May 18, 2023, and was discovered on May 19, 2023. Affected data included names, addresses, driver's license numbers, emails, phone numbers, and dates of birth. Progressive blocked access, launched an investigation, and offered 24 months of complimentary credit monitoring via Experian.
California clockDiscovered May 19, 2023 → Notified Aug 1, 202374d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_13eee63ab5d15a5bWashington State AGfiled 2023-08-01Candidate
- bd_3d21615407581ec9Hawaii State AGfiled 2023-08-01Verified
- bd_9232e4d288f699c0Maine State AGfiled 2023-08-01Verified
- bd_dcb87249ca236b46Oregon State AGfiled 2023-08-01Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571139
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2023
- Raw hash
- 5c29202ea5f0dc9a2c9b822c615592146d586fe2b3ed5d2714c4624b4967dd51
Reporting entity
- Name
- PROGRESSIVE CASUALTY INSURANCE COMPANYnorm: progressive casualty insurance
Victim entity
- Name
- PROGRESSIVE CASUALTY INSURANCE COMPANYnorm: progressive casualty insurance
Incident
- Discovered
- May 19, 2023
- Materiality determined
- —
- Notification sent
- Aug 1, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Third-party call center provider
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- CA 60-day late · 74d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 19, 2023→ Notified: Aug 1, 202374d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.