HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Allied Services Division Welfare Fund
bd_ea461a4f5e45912b · schema v1 · pii pii-v1
Full breach record for Allied Services Division Welfare Fund →Allied Services Division Welfare Fund reported that an unauthorized individual gained access to an employee email account between October 9, 2024, and November 26, 2024. The incident was discovered on November 25, 2024. Affected data includes names, addresses, Social Security numbers, health insurance information, and financial account details. The Fund engaged external cybersecurity professionals and is offering one month of complimentary identity monitoring services to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7876859b27b2e816New Hampshire State AGfiled 2025-08-04(5d gap)Verified
- bd_4473822e969ee373Montana State AGfiled 2025-10-02(64d gap)Verified
- bd_7b749ada8d94bc85California State AGfiled 2025-10-02(64d gap)Verified
- bd_c8075fd8cda090d1Texas State AGfiled 2025-10-03(65d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-606339
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 30, 2025
- Raw hash
- 47d051909f5f2b9d7396aa579d8d74facc7dba5bc21d9799fff41c4b534a677d
Reporting entity
- Name
- Allied Services Division Welfare Fundnorm: allied services division welfare
Victim entity
- Name
- Allied Services Division Welfare Fundnorm: allied services division welfare
Incident
- Discovered
- Nov 25, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 35 weeks(247 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.