Social EngineeringPhishingCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
INJURED WORKERS PHARMACY, LLC
bd_e517b01e2e7103c5 · schema v1 · pii pii-v1
Full breach record for INJURED WORKERS PHARMACY, LLC →Injured Workers Pharmacy (IWP) disclosed a data breach affecting 503 Rhode Island residents. An unknown actor accessed seven IWP employee email accounts between January 16, 2021, and May 12, 2021, following suspicious activity detected on May 11, 2021. The compromised accounts contained patient information, including names and government identifiers. IWP reset passwords, enhanced security measures, and reported the incident to regulators.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0da3cefbaa48d84aOregon State AGfiled 2022-02-03Verified by operator
- bd_89cd2fca5e2a5b73Montana State AGfiled 2022-02-03Verified by operator
- bd_cbd9b158361df2b7Maine State AGfiled 2022-02-03Verified by operator
- bd_e914dd5cce38958dNew Hampshire State AGfiled 2022-02-07(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 51d gap
- bd_0366b430e038b111Delaware State AGfiled 2021-12-14(51d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/02/Pages-from-Notice-of-Data-Event-IWP-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 3, 2022
- Raw hash
- d6ce7d4592d489739297d3b46996362763f59a4adb4c12e63b460eee7c5f3f1b
Reporting entity
- Name
- INJURED WORKERS PHARMACY, LLCnorm: injured workers pharmacy
Victim entity
- Name
- INJURED WORKERS PHARMACY, LLCnorm: injured workers pharmacy
Incident
- Discovered
- May 11, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 503
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- reported this event to government regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 38 weeks(268 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.