Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
SAG-AFTRA Health Plan
bd_e32d3742be322d96 · schema v1 · pii pii-v1
Full breach record for SAG-AFTRA Health Plan →SAG-AFTRA Health Plan experienced a data breach after an employee's email account was compromised via a phishing email. Unauthorized access occurred between September 17 and 18, 2024. The incident exposed personal information including names, Social Security numbers, and potentially health insurance claims data for some plan participants. The Plan contained the incident, engaged third-party experts, notified law enforcement, and is offering one year of identity theft protection to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_b608666f3ea2f0c6HHS OCRfiled 2024-12-02Verified
- bd_d20c10fe5f79e754New Hampshire State AGfiled 2024-12-02Verified
- bd_e1a4e08cafa89054Montana State AGfiled 2024-12-02Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595543
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 2, 2024
- Raw hash
- 7b8d8432f18391398c6a430fdbb6468e471afe8dbba9ff4b5be49c05b4168845
Reporting entity
- Name
- SAG-AFTRA Health Plannorm: sag aftra health plan
Victim entity
- Name
- SAG-AFTRA Health Plannorm: sag aftra health plan
Incident
- Discovered
- Sep 18, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.