AccidentalMisconfigurationData ExfiltratedPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
BackNine Insurance and Financial Services, Inc.
bd_f6266be19daceb2c · schema v1 · pii pii-v1
Full breach record for BackNine Insurance and Financial Services, Inc. →BackNine Insurance and Financial Services, Inc. disclosed a data security incident involving a coding error that exposed insurance and annuity applications in a publicly accessible cloud storage folder. The breach affected personal information (PI) and protected health information (PHI) of policyholders. BackNine secured the folder, engaged outside experts, and offered credit monitoring and identity protection services to affected individuals.
California clockDiscovered Jul 12, 2021 → Notified Aug 13, 202132d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4ce68e7cc28dddcfWashington State AGfiled 2021-08-17Verified
- bd_bf4eff0871308114Oregon State AGfiled 2021-08-17Verified
- bd_a3139dfc8b843b51Maine State AGfiled 2021-08-18(1d gap)Verified
- bd_04b76c0a63bd345dMontana State AGfiled 2021-08-12(5d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543955
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2021
- Raw hash
- 14334846b29cd43c6e7ea4fcc2ece7c30845621cd555867a8bd844972e17a000
Reporting entity
- Name
- BackNine Insurance and Financial Services, Inc.norm: backnine insurance and financial
Victim entity
- Name
- BackNine Insurance and Financial Services, Inc.norm: backnine insurance and financial
Incident
- Discovered
- Jul 12, 2021
- Materiality determined
- —
- Notification sent
- Aug 13, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1535 Untrusted Cloud Compute
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 32d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 12, 2021→ Notified: Aug 13, 202132d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.