Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Lyons Companies
bd_e27c8a0ce50b46e4 · schema v1 · pii pii-v1
Full breach record for Lyons Companies →Lyons Companies, an insurance brokerage firm, disclosed a phishing incident involving unauthorized access to two employee email accounts. The breach occurred between February 4 and March 12, 2019, and was discovered on March 12, 2019. The incident potentially exposed customer data, including names, Social Security numbers, and dates of birth, contained in the compromised emails. Lyons engaged forensic experts, enhanced system security, and provided complimentary identity monitoring services to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8d3a13f40343ed00HHS OCRfiled 2019-08-23Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/09/Lyons-Companies-Sample-Notice-1.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2019
- Raw hash
- 4f89d1ed5f9dff8f19b6506f305db784db1128b9db0301898b5d698133c9cf5b
Reporting entity
- Name
- Lyons Companiesnorm: lyons companies
Victim entity
- Name
- Lyons Companiesnorm: lyons companies
Incident
- Discovered
- Mar 12, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Reporting this incident to appropriate regulatory authorities
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(164 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.