Social EngineeringPhishingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICPIILowContained
American Federation of Musicians and Employers' Pension Fund
bd_ed0f72b54a8ca9e1 · schema v1 · pii pii-v1
Full breach record for American Federation of Musicians and Employers' Pension Fund →The American Federation of Musicians and Employers' Pension Fund disclosed a phishing incident where an employee's email account was compromised between May 22, 2020, and August 18, 2020. The breach exposed names and other personal information of plan participants. The organization engaged forensic specialists, secured the account, and offered 12 months of credit monitoring via TransUnion to affected individuals.
California clockDiscovered Aug 18, 2020 → Notified Dec 11, 2020115d ✗ CA 60-day late21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1de5f609fa8e90b7Montana State AGfiled 2021-01-11Candidate
- bd_a73db7963aed25bbMaine State AGfiled 2021-01-12(1d gap)Verified
- bd_bbbbe1f72be2995aMaine State AGfiled 2021-01-12(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198413
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2021
- Raw hash
- 20291074bc6c58f8a3ad73b99d7ae3a64fa8bf76a87da352f15c4fc971f2b55c
Reporting entity
- Name
- American Federation of Musicians and Employers' Pension Fundnorm: american federation of musicians and employers pension
Victim entity
- Name
- American Federation of Musicians and Employers' Pension Fundnorm: american federation of musicians and employers pension
Incident
- Discovered
- Aug 18, 2020
- Materiality determined
- —
- Notification sent
- Dec 11, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified regulatory authorities, as required by law
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 weeks(146 days from discovery to filing)
- Compliance flags
- CA 60-day late · 115d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 18, 2020→ Notified: Dec 11, 2020115d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.