MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Smile Brands Group Inc.
bd_ee44aad4e560c1f0 · schema v1 · pii pii-v1
Full breach record for Smile Brands Group Inc. →Smile Brands Inc. reported a ransomware attack on April 23-24, 2021, affecting systems containing Protected Health Information (PHI). The incident involved data encryption and unauthorized acquisition of customer data, including names, SSNs, dates of birth, and health insurance/diagnosis info. The company notified law enforcement, engaged cybersecurity firms, terminated access, and offered 1 year of Experian IdentityWorks.
California clockDiscovered Apr 24, 2021 → Notified Aug 9, 2021107d ✗ CA 60-day late19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_97047e3f9d80ac21Montana State AGfiled 2021-09-28(25d gap)Verified
- bd_74aefa527fd325d9Maine State AGfiled 2021-10-08(35d gap)Verified
- bd_b38f99f429ded2c9Washington State AGfiled 2021-10-08(35d gap)Verified
- bd_bdaabc04103b621aOregon State AGfiled 2021-10-08(35d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-544924
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 3, 2021
- Raw hash
- 5825408463b35fdced9f552a0ee88580c4ad06922be6879f03e021e8e673ac12
Reporting entity
- Name
- Smile Brands Group Inc.norm: smile brands
Victim entity
- Name
- Smile Brands Group Inc.norm: smile brands
Incident
- Discovered
- Apr 24, 2021
- Materiality determined
- —
- Notification sent
- Aug 9, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- CA 60-day late · 107d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 24, 2021→ Notified: Aug 9, 2021107d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.