AccidentalMisconfigurationTargetedIDENTITY_BASICLowContained
Skyward
bd_f4a32cd5a2389d1a · schema v1 · pii pii-v1
Full breach record for Skyward →Skyward Service Company notified South Carolina and other states of a data incident where a database containing personal information (names, data elements) was publicly discoverable due to a miscalibration in database settings. The incident was discovered on April 5, 2025, when documents were found on the dark web. No evidence of fraud or identity theft was found. Skyward remediated the settings and is enhancing its review process.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/ELN-24803%20Skyward%20Specialty%20Insurance%20Adult%20No%20CM%20r1prf-c.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 10, 2025
- Raw hash
- 2ca524d63ce6c3464d65e4c96e497c28fb490197c9ed87fa56e57eb7f1252cef
Reporting entity
- Name
- Skywardnorm: skyward
- Domain
- go-skyward.com
Victim entity
- Name
- Skywardnorm: skyward
- Domain
- go-skyward.com
Incident
- Discovered
- Apr 5, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.