HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
EMC NATIONAL LIFE COMPANY
bd_e91b811e21457c6d · schema v1 · pii pii-v1
Full breach record for EMC NATIONAL LIFE COMPANY →EMC National Life Company reported a data security incident where unauthorized access occurred between Dec 28-30, 2021. The breach exposed personal information including names and Social Security numbers. The company engaged third-party forensic experts, coordinated with law enforcement and the Iowa Insurance Division, and offered one year of Experian IdentityWorks credit monitoring to affected individuals. No misuse of information was believed to have occurred.
California clockDiscovered Mar 9, 2022 → Notified Mar 9, 20220d ✓ CA 60-day OK4 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_74b57e86f63be467Montana State AGfiled 2022-04-08Candidate
- bd_864052ad7778de46Maine State AGfiled 2022-04-08Verified
- bd_c2aee2bf6127a5bfWashington State AGfiled 2022-04-08Verified
- bd_fb8292a8b358689cOregon State AGfiled 2022-04-21(13d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552392
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2022
- Raw hash
- c8aceef1bbf31db5cf34747d0a33aab63c454f09a9653cafc979b5815b18af8f
Reporting entity
- Name
- EMC NATIONAL LIFE COMPANYnorm: emc national life
Victim entity
- Name
- EMC NATIONAL LIFE COMPANYnorm: emc national life
Incident
- Discovered
- Mar 9, 2022
- Materiality determined
- —
- Notification sent
- Mar 9, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- coordinated with law enforcement and the Iowa Insurance Division
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 9, 2022→ Notified: Mar 9, 20220d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.