HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
GMGS Risk Management & Insurance Services
bd_e0d909f4c8a7f461 · schema v1 · pii pii-v1
Full breach record for GMGS Risk Management & Insurance Services →GMGS Risk Management & Insurance Services discovered on December 21, 2020, that an employee's email account was accessed by an unknown individual. The incident potentially exposed PII (name, SSN, driver's license, DOB) and PHI (medical/health insurance info). Forensic investigation completed in Feb 2021; data review confirmed exposure in June 2021. GMGS implemented MFA and offered credit monitoring.
California clockDiscovered Dec 21, 2020 → Notified Oct 22, 2021305d ✗ CA 60-day late45 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547125
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 2, 2021
- Raw hash
- 4d311314da8c424f2db69771c4f8e0180bc7cc39253cb4c8b6ccdb8aababf8be
Reporting entity
- Name
- GMGS Risk Management & Insurance Servicesnorm: gmgs risk management insurance
- Domain
- gmgs.com
Victim entity
- Name
- GMGS Risk Management & Insurance Servicesnorm: gmgs risk management insurance
- Domain
- gmgs.com
Incident
- Discovered
- Dec 21, 2020
- Materiality determined
- —
- Notification sent
- Oct 22, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 45 weeks(316 days from discovery to filing)
- Compliance flags
- CA 60-day late · 305d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 21, 2020→ Notified: Oct 22, 2021305d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.