Morley Companies, Incorporated
ent_019e0be5742653a126d66ccb76d072de
Disclosures
16
State AG · HHS OCR · 11 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
659,339
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Morley Companies, Incorporated
- Normalized
- morley companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493003LWCS17QP5WO46
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (16)newest first
- Washington State AGas victim2022-03-21
Morley Companies, Inc. reported a ransomware incident affecting approximately 42,633 Washington residents. Unauthorized access occurred between July 20 and September 2, 2021, with discovery on August 1, 2021. Personal information including SSNs, DOBs, driver's licenses, and health data was compromised. Morley engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring.
- California State AGas victim2022-03-21
Morley Companies, Inc., a Michigan-based health plan processing firm, experienced a ransomware-type malware attack beginning August 1, 2021, which prevented access to certain files and resulted in unauthorized access to personal information including Social Security numbers. The company discovered the incident, engaged third-party forensic specialists, and confirmed affected individuals in March 2022. IDX credit and identity monitoring services were offered for 24 months.
- New Hampshire State AGas victim2022-03-21
Morley Companies, Inc. reported a supplemental data security incident to the New Hampshire Attorney General on March 21, 2022. The incident involved ransomware-type malware affecting systems starting August 1, 2021. Approximately 30 individuals were notified, with data potentially including SSNs, names, DOBs, driver's license numbers, and health information. Morley engaged forensic specialists and provided 24 months of credit/identity monitoring via IDX.
- Oregon State AGas victim2022-02-08
Morley Companies, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-02-08. The breach occurred during 7/20/2021 - 9/2/2021. The breach was discovered on 1/20/2022. 590,785 individuals were affected. Notice was sent on 2/8/2022.
- California State AGas victim2022-02-01
Morley Companies, Inc., a Michigan-based firm processing information for health plans, experienced a ransomware attack beginning August 1, 2021. The malware prevented access to files and allowed unauthorized access to data containing personal information including Social Security numbers. On January 18, 2022, the company confirmed affected individuals. Notification letters were sent February 1, 2022. IDX credit/identity monitoring (24 months) was offered to affected individuals.
- New Hampshire State AGas victim2022-02-01
Morley Companies, Inc. filed a supplemental notification with the New Hampshire Attorney General regarding a ransomware incident affecting 35 individuals. The attack began on August 1, 2021, encrypting files and preventing system access. The breach exposed Social Security numbers, names, dates of birth, driver's license numbers, and health information. Notifications were mailed on February 1, 2022, offering 24 months of credit and identity monitoring through IDX.
- Maine State AGas victim2022-02-01
Morley Companies, Inc. reported a data breach affecting 62 Maine residents. The breach, an external system hacking incident, occurred on July 20, 2021, and was discovered on January 26, 2022. The compromised information includes names and Social Security numbers. Affected individuals were notified on February 1, 2022, and offered 12 months of credit and identity theft protection services through IDX.
- MICHIGANHHS OCRas victim2022-02-01
Morley Companies, Inc. reported to HHS on 2022-02-01 a Hacking/IT Incident affecting 659,194 individuals. Breached information located on Network Server. The incident involved PHI including names, addresses, SSNs, and treatment data. The entity provided credit monitoring and implemented security safeguards.
- South Carolina State AGas victim2022-01-27
Morley Companies, Inc., a health plan data processor, experienced a ransomware incident beginning August 1, 2021. Ransomware malware prevented access to files and unauthorized access occurred to files containing personal information, including Social Security numbers. The company engaged forensic specialists and confirmed involvement of affected individuals on January 18, 2022. No financial information was involved. The company is offering 24 months of credit and identity monitoring.
- Massachusetts State AGas victim2022-01-26
Morley Companies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-01-26. 756 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2022-01-26
Morley Companies, Inc. notified individuals in Montana of a data security incident beginning August 1, 2021, discovered December 22, 2021. Unauthorized access may have exposed names, DOBs, SSNs, driver's licenses, and health information. No evidence of misuse was found. The company engaged cybersecurity experts and offered complimentary credit and identity monitoring via IDX.
- Indiana State AGas victim2022-01-26
Morley Companies, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-07-20 and was reported on 2022-01-26. 24,156 Indiana residents were affected. 659,339 individuals affected in total.
- Maine State AGas victim2022-01-26
Morley Companies, Inc. experienced an external system breach (hacking) that was discovered on December 22, 2021. The breach occurred on July 2, 2021, and affected 2 Maine residents. The compromised information includes names or other personal identifiers in combination with financial account numbers or credit/debit card numbers and their security codes, access codes, passwords, or PINs. Written notifications were sent to affected consumers on January 26, 2022, and 12 months of credit and identity theft protection services were offered through IDX.
- New Hampshire State AGas victim2022-01-26
Morley Companies Inc. notified the NH Attorney General of a data security incident discovered on August 1, 2021. An unknown actor may have gained unauthorized access to the network. Personal information, including names, dates of birth, Social Security numbers, driver's license numbers, and health information, may have been involved for approximately 2 New Hampshire residents. The investigation is ongoing. Morley engaged cybersecurity experts, notified the FBI, and is offering credit monitoring services.
- Illinois State AGas victim2022-01-01
MORLEY COMPANIES, INC filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-199). The register records the breach as discovered on February 8, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2022-01-01
MORLEY COMPANIES, INC filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-066). The register records the breach as discovered on August 1, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.