Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
The Union Labor Life Insurance Company
bd_ebf082c9ce5a32a9 · schema v1 · pii pii-v1
Full breach record for The Union Labor Life Insurance Company →The Union Labor Life Insurance Company reported that on April 1, 2019, an unauthorized external user accessed an employee's Outlook email account via a fraudulent link from a trusted business partner. The incident potentially exposed personal information of participants in medical stop loss or group life insurance policies, including names, addresses, and possibly Social Security numbers. The company disabled the account within 90 minutes, engaged forensic investigators, and offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148434
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2019
- Raw hash
- ac828519a4a3ea3500fccd22ec11120769ee83f6a2e49d6320240b2eb2b499ab
Reporting entity
- Name
- The Union Labor Life Insurance Companynorm: the union labor life insurance
Victim entity
- Name
- The Union Labor Life Insurance Companynorm: the union labor life insurance
Incident
- Discovered
- Apr 1, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.