HackingTechnologyProfessional ServicesInformationStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryData ExfiltratedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Ventiv Technology Inc.
bd_dd1445297e59517d · schema v1 · pii pii-v1
Full breach record for Ventiv Technology Inc. →Ventiv Technology, Inc. reported a security incident in which an unknown individual accessed certain employee email accounts hosted on Office365 without authorization between October 14 and December 8, 2017. The IT department received reports of suspicious activity on December 5, 2017. A forensic firm was engaged to investigate. Emails and attachments may have contained names and Social Security numbers of workers' compensation claimants and healthcare providers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b82c10cfabd77738Montana State AGfiled 2018-02-28(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134144
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 1, 2018
- Raw hash
- e23b61f5ce93f4b15c73f67d5f7ceaca784f4dea1706ff69dacf605f4957bcf4
Reporting entity
- Name
- Ventiv Technology Inc.norm: ventiv technology
Victim entity
- Name
- Ventiv Technology Inc.norm: ventiv technology
- Industry
- TechnologyllmProfessional Servicesllm
Incident
- Discovered
- Dec 5, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.