DisclosureLens
HackingTelecom & MediaInformationHacking OtherCustomer Data InvolvedPIICredentialsFinancialLowContained

CenturyLink Communications

bd_ed100af19ad3354d · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 20, 2020

Filed

Sep 25, 2020

To disclose

5 weeks

Affected

1scope not determined

Confidence

50%
Full breach record for CenturyLink Communications3 incidents on file

CenturyLink Communications identified a breach of their external systems that took place between August 20, 2020, and August 31, 2020. The breach was discovered on or around August 20, 2020. The incident resulted in unauthorized access to customer account information, including names, contact details, credentials, and billing and payment information. Approximately 1,942 individuals were affected in total, with one resident of Maine among them. Affected individuals were notified in writing starting on September 21, 2020.

Maine clockDiscovered Aug 20, 2020Filed with AG Sep 25, 202036d ME AG >30d5 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 5 weeks / 36 days

Aug 20, 2020

Begins

Aug 20, 2020

Discovered

Sep 25, 2020

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.