DisclosureLens
AccidentalFinancial ServicesFinanceMisconfigurationSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)PHIMinorMediumResolved

CSAC-EXCESS INSURANCE AUTHORITY

bd_f923cf2bdda82af8 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 9, 2015

Filed

Nov 10, 2015

To disclose

9 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for CSAC-EXCESS INSURANCE AUTHORITY

CSAC-Excess Insurance Authority notified the California AG of a breach involving its third-party vendor, Systema Software. A security researcher identified a configuration error in Systema's claims management website that allowed access to a temporary data backup. The researcher self-reported the issue to the Texas AG. Affected data included names, SSNs, driver's license numbers, and medical information. No unauthorized use was believed to have occurred.

Incident timeline

undetected · 6 days
discovery → filing · 9 weeks / 62 days

Sep 3, 2015

Begins

Sep 9, 2015

Discovered

Nov 10, 2015

Filed

vs. sector median

on median

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.