HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTMediumContained
Voya Financial Advisors, Inc.
bd_ed198ddb056bd870 · schema v1 · pii pii-v1
Full breach record for Voya Financial Advisors, Inc. →Voya Financial Advisors, Inc. disclosed that perpetrators used a financial advisor's stolen personal information to gain unauthorized access to VFA's systems and client records on or shortly after April 13, 2016. The incident involved potential exposure of names, addresses, dates of birth, partial SSNs, government IDs, employer info, and financial account details. VFA detected and remediated the access within hours, notified the FBI, and offered one year of credit monitoring to affected individuals.
California clockDiscovered Apr 13, 2016 → Notified Apr 21, 20168d ✓ CA 60-day OK8 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-61193
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2016
- Raw hash
- 318aec28aaae31c669068f8a62b7f930f296dad9861fd8a24de0d988a9189cb1
Reporting entity
- Name
- Voya Financial Advisors, Inc.norm: voya financial advisors
Victim entity
- Name
- Voya Financial Advisors, Inc.norm: voya financial advisors
Incident
- Discovered
- Apr 13, 2016
- Materiality determined
- —
- Notification sent
- Apr 21, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 8d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 13, 2016→ Notified: Apr 21, 20168d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.