CIC Group, Inc.
ent_019e61b0dd419a11105da5819aee77a9
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,500
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CIC Group, Inc.
- Normalized
- cic group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300V3OJBC4OF75S38
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Aon— per SEC Exhibit 21 filing
Disclosure history (5)newest first
- Montana State AGas victim2023-04-23
CIC Group, Inc. notified Montana residents of a ransomware attack discovered on March 28, 2023. The attack encrypted/destroyed data and potentially exfiltrated PII including SSNs and passport info. The company engaged forensic investigators and law enforcement, and is offering 24 months of credit monitoring.
- Oregon State AGas victim2023-04-23
CIC Group, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-04-23. The breach occurred during 3/28/2023. The breach was discovered on 4/13/2023. 4,500 individuals were affected. Notice was sent on 4/21/2023.
- Indiana State AGas victim2023-04-21
CIC Group Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-03-28 and was reported on 2023-04-21. 294 Indiana residents were affected. 4,500 individuals affected in total.
- Massachusetts State AGas victim2023-04-21
CIC Group, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-04-21. 7 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-04-21
CIC Group, Inc. experienced a ransomware attack on March 28, 2023, which encrypted or destroyed data on affected systems. On April 13, 2023, the threat actor indicated that personal information, including names, addresses, SSNs, and passport info, was exfiltrated. The company disabled systems, engaged forensic investigators, notified law enforcement, and is offering 24 months of credit monitoring.