MalwareRansomwareData ExfiltratedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Cirrus Asset Management, Inc.
bd_eccdc66e3bf7d175 · schema v1 · pii pii-v1
Full breach record for Cirrus Asset Management, Inc. →Cirrus Asset Management, Inc. detected a malware infection on its network on November 12, 2021. The attackers claimed to have removed data and demanded payment. The breach window is November 11-12, 2021. Personal information, including full names and Social Security numbers, may have been accessed. The company contained the threat, engaged forensic investigators, and is offering credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_19771b36f547bb73Maine State AGfiled 2021-12-15Candidate
- bd_e34c7f5e9e02b1abWashington State AGfiled 2021-12-16(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548588
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2021
- Raw hash
- fb8a8f0929e9d39e3be473a07cfe399ec4f3a3dc192a6e5a8c790e55caa6c5e9
Reporting entity
- Name
- Cirrus Asset Management, Inc.norm: cirrus asset management
Victim entity
- Name
- Cirrus Asset Management, Inc.norm: cirrus asset management
Incident
- Discovered
- Nov 12, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.