Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
EyeMed Vision Benefits
bd_dd7329e4945257ee · schema v1 · pii pii-v1
Full breach record for EyeMed Vision Benefits →EyeMed, a vision benefits administrator, disclosed a data breach where an unauthorized individual accessed an EyeMed email mailbox and sent phishing emails to contacts in the address book. Access occurred from June 24, 2020, to July 1, 2020. EyeMed discovered the incident on July 1, 2020, blocked access, and engaged a cybersecurity firm. Personal information of individuals receiving vision benefits may have been viewed or copied. EyeMed implemented password changes, security training, and provided two years of free identity monitoring via Kroll.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_34d1a19c2cb74c79California State AGfiled 2020-12-11Verified
- bd_cf86ae44e1360d1cMaine State AGfiled 2020-11-30(11d gap)Verified
- bd_03f6bce6b4d9bc45South Carolina State AGfiled 2021-01-27(47d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/03/EyeMed-Individual-Notice-Template-10.21.2020-Reseller.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2020
- Raw hash
- 04479eba318c2e131f4ec0b9eedbdf365ffa38eb1bb741b2308900ff6d1de817
Reporting entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Victim entity
- Name
- EyeMed Vision Benefitsnorm: eyemed vision benefits
- Domain
- eyemed.com
Incident
- Discovered
- Jul 1, 2020
- Materiality determined
- —
- Notification sent
- Oct 21, 2020
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(163 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.