DisclosureLens
Social EngineeringTelecom & MediaInformationPhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDMediumContained

CenturyLink

bd_df381037acd1f901 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 1, 2017

Filed

Feb 20, 2017

To disclose

19 days

Affected

26state residents only

Linked

3 filings

Confidence

66%
Full breach record for CenturyLink2 incidents on file

CenturyLink notified Montana employees that an email account was compromised via phishing on or around Jan 30, 2017. Detected Feb 1, 2017. Exposed PII including names, addresses, SSNs, and DOBs. No financial data involved. CenturyLink stopped spam, offered 1-year Experian ProtectMyID, and provided security training.

Incident timeline

undetected · 2 days
discovery → filing · 19 days

Jan 30, 2017

Begins

Feb 1, 2017

Discovered

Feb 20, 2017

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Montana State AGFeb 20 · first · this page

Pattern: first filing Feb 20 (MT), last Feb 28 (MA) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.