Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSHEALTH_BASICMediumContained
Athens Insurance Agency
bd_e525c1186e8e42fa · schema v1 · pii pii-v1
Full breach record for Athens Insurance Agency →Athens Insurance Services, Inc. reported a cybersecurity incident involving unauthorized access to an employee email account between July 1, 2019, and September 17, 2019. The breach potentially exposed personal information including names, SSNs, driver's license numbers, financial account numbers, and health information. Athens engaged forensic investigators, secured the account, and offered one year of credit monitoring to affected individuals.
California clockDiscovered Sep 17, 2019 → Notified Mar 17, 2020182d ✗ CA 60-day late31 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_780dc2de5b333aefCalifornia State AGfiled 2020-03-06(48d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-189397
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2020
- Raw hash
- 6dece559815cd7f31c4478ea7e8ab6f983ce4a95d4f3b7dbdd9663b3c889a39b
Reporting entity
- Name
- Athens Insurance Agencynorm: athens insurance agency
- Domain
- athensins.com
Victim entity
- Name
- Athens Insurance Agencynorm: athens insurance agency
- Domain
- athensins.com
Incident
- Discovered
- Sep 17, 2019
- Materiality determined
- —
- Notification sent
- Mar 17, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 31 weeks(219 days from discovery to filing)
- Compliance flags
- CA 60-day late · 182d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 17, 2019→ Notified: Mar 17, 2020182d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.