HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Porter & Curtis, LLC
bd_f436f3bdfde8db40 · schema v1 · pii pii-v1
Full breach record for Porter & Curtis, LLC →Porter & Curtis LLC, an insurance procurement and risk management firm, notified California regulators of a data breach involving a business partner. Unauthorized access to Porter & Curtis data occurred between February 12 and March 18, 2020. The incident potentially exposed personal information, including names and government identifiers, of individuals who provided data to the firm. Porter & Curtis reported the incident to the FBI, engaged cybersecurity firms, and offered one year of credit monitoring via Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537688
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 2, 2021
- Raw hash
- 4124a0174bbe6dda366daf4192575704400aa71e50e78fdbc28ac688bbd2081c
Reporting entity
- Name
- Porter & Curtis, LLCnorm: porter curtis
Victim entity
- Name
- Porter & Curtis, LLCnorm: porter curtis
Incident
- Discovered
- Mar 18, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Reported the incident to the Federal Bureau of Investigation
- Initial access
- supply_chain
Compliance
- Time to disclose
- 46 weeks(321 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.