DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsCustomer Data InvolvedIdentity (basic)Government IDPHIHealth (basic)MediumContained

GMGS Risk Management & Insurance Services

bd_e0d909f4c8a7f461 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 21, 2020

Filed

Nov 2, 2021

To disclose

45 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for GMGS Risk Management & Insurance Services

GMGS Risk Management & Insurance Services discovered on December 21, 2020, that an employee's email account was accessed by an unknown individual. The incident potentially exposed PII (name, SSN, driver's license, DOB) and PHI (medical/health insurance info). Forensic investigation completed in Feb 2021; data review confirmed exposure in June 2021. GMGS implemented MFA and offered credit monitoring.

California clockDiscovered Dec 21, 2020Notified Oct 22, 2021305d CA 60-day late45 weeks discovery → filing

Incident timeline

discovery → filing · 45 weeks / 316 days

Dec 21, 2020

Begins

Dec 21, 2020

Discovered

Nov 2, 2021

Filed

vs. sector median

+37 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.