Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
CRC Insurance Services, LLC
bd_ef08d8fabbad4f62 · schema v1 · pii pii-v1
Full breach record for CRC Insurance Services, LLC →CRC Insurance Services LLC reported a cybersecurity incident to the Idaho Attorney General on July 26, 2023. Unauthorized access occurred via a phishing scheme targeting employee email accounts between January 13 and January 21, 2023. The incident affected 36 Idaho residents, exposing names, SSNs, driver's license numbers, passport numbers, financial account numbers, and health information. CRC engaged forensic vendors, reset passwords, reconfigured APIs, and offered one year of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_609f8e75669d9e57California State AGfiled 2023-07-26Candidate
- bd_684512eb7188bc5dMontana State AGfiled 2023-07-26Verified
- bd_97f391745ea166b7Vermont State AGfiled 2023-07-19(7d gap)Verified
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2023/07/7-26-2023-CRC-Insurance-Services-LLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2023
- Raw hash
- 86c5a9201bf88248d35c13880afb6ccbed328f8e3a3274fa681a8aa33f0fdddc
Reporting entity
- Name
- CRC Insurance Services, LLCnorm: crc insurance
Victim entity
- Name
- CRC Insurance Services, LLCnorm: crc insurance
Incident
- Discovered
- Jan 18, 2023
- Materiality determined
- —
- Notification sent
- Jul 26, 2023
- Affected individuals
- 36
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators in other states where impacted persons are resident
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.