Social EngineeringPhishingEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
MJ Insurance, Inc
bd_e62b2e56217dd0aa · schema v1 · pii pii-v1
Full breach record for MJ Insurance, Inc →MJ Insurance, Inc. disclosed that an unknown individual gained access to an employee's email account on September 26, 2018, likely via phishing. The breach potentially exposed personally identifiable information including names, dates of birth, driver's license numbers, and Social Security numbers. No financial account information was involved. The company changed credentials, engaged forensic investigators, and is offering credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143317
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 27, 2018
- Raw hash
- 983e78f77b81b49fe8ceb7a46dfe97c5a2621d0cac88ca684325abe485361fd6
Reporting entity
- Name
- MJ Insurance, Incnorm: mj insurance
Victim entity
- Name
- MJ Insurance, Incnorm: mj insurance
Incident
- Discovered
- Sep 26, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.