Welk Resort Group, Inc.
ent_019e6283754e2884b26d672f5174d1cd
Disclosures
9
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,320
as filed · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Welk Resort Group, Inc.
- Normalized
- welk resort— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300XZ6KX7JBQLEM74
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- Montana State AGas victim2019-02-22
Welk Resort Group, Inc. notified Montana residents of a data breach involving unauthorized access to an employee email account between July 24 and August 2, 2018. The incident, likely caused by phishing, exposed names and dates of birth. No evidence of misuse was found. The company offered one year of credit monitoring.
- New Hampshire State AGas victim2019-02-22
Welk Resort Group notified the NH AG of unauthorized access to an employee email account between July 24 and August 2, 2018. Discovered Aug 2, 2018. Affected ~3 NH residents with PII including SSN, DL, and payment card info. No evidence of misuse. Forensic investigators engaged. Credit monitoring offered.
- Massachusetts State AGas victim2019-02-22
Welk Resort Group Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-02-22. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-02-22
Welk Resort Group, Inc. experienced unauthorized access to an employee email account between July 24, 2018, and August 2, 2018. The incident was discovered on August 2, 2018. Approximately 1,320 California residents were affected, with potential exposure of names, addresses, Social Security numbers, driver's license numbers, financial account numbers, and health information. The company engaged forensic investigators, contained the incident, and is providing credit monitoring services to affected individuals.
- California State AGas victim2018-08-01
Welk Resort Group, Inc. disclosed that unauthorized actors accessed certain employee email accounts between November 29 and December 4, 2017. The company discovered unusual activity on December 4, 2017. Personal information, including names, SSNs, driver's license numbers, financial account info, and medical history, may have been present in the impacted emails. Approximately 1,034 California residents were affected. The investigation is ongoing. Welk is offering one year of credit monitoring and identity restoration services.
- Massachusetts State AGas victim2018-07-25
Welk Resort Group Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-07-25. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-07-25
Welk Resort Group, Inc. notified the NH AG of unauthorized access to employee email accounts occurring between Nov 29 and Dec 4, 2017. Discovered Dec 4, 2017. Affected approx. 2 NH residents. Data included PII, SSN, financial info, credentials, and PHI. No evidence of misuse. Credit monitoring offered.
- Montana State AGas victim2018-07-25
Welk Resort Group, Inc. notified Montana residents of a data breach involving unauthorized access to employee email accounts. The incident occurred between November 29 and December 4, 2017, and was discovered on December 4, 2017. Personal information (names) of a small percentage of owners was present in affected emails. No evidence of misuse was found. The company offered 12 months of credit monitoring.
- California State AGas victim2016-11-04
Welk Resort Group, Inc. reported the theft of a company laptop from an employee's home on October 5, 2016. The laptop may have contained employee personal information including names, Social Security numbers, addresses, dates of birth, and benefit plan participation information. The company launched an investigation and reported the theft to local police. No evidence of unauthorized access or misuse was found at the time of notification. Credit monitoring services were offered to affected employees.