Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICPHIHEALTH_BASICLowContained
Capitol Administrators, Inc
bd_eaa2615eb5b27269 · schema v1 · pii pii-v1
Full breach record for Capitol Administrators, Inc →Capitol Administrators, Inc. notified the California Attorney General's Office of a phishing incident occurring between January 7 and January 24, 2018. An unauthorized individual accessed emails and attachments containing plan participants' names and personal/medical data. Capitol engaged forensic investigators, secured accounts, implemented MFA, and provided one year of Kroll identity monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4ac3f5743079772fHHS OCRfiled 2018-05-11Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136119
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2018
- Raw hash
- 0089616e03d792e06e8e3c4d617ce9f6ba92c7884d1d6d618ce48e00f7b05a6e
Reporting entity
- Name
- Capitol Administrators, Incnorm: capitol administrators
Victim entity
- Name
- Capitol Administrators, Incnorm: capitol administrators
Incident
- Discovered
- Mar 30, 2018
- Materiality determined
- Jan 24, 2018
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.