The Affiliated Group
ent_1ee663a1354ef54a47d395e1
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,289
as filed · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Affiliated Group
- Normalized
- the affiliated— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- New Hampshire State AGas victim2018-09-27
The Affiliated Group (TAG) notified the NH AG of a phishing incident resulting in unauthorized access to an employee email account. The actor sent phishing emails to harvest credentials. The account contained PHI and PII (SSN, medical record numbers, financial account info) of approximately 31 NH residents. TAG disabled the account, engaged forensic investigators, and provided 12 months of credit monitoring.
- California State AGas victim2018-09-19
The Affiliated Group (TAG) confirmed on March 28, 2018, that an unauthorized actor gained access to one employee email account following a phishing incident in November 2017. The attacker used the account to send phishing emails. A review determined that names, Social Security numbers, medical record numbers, limited treatment information, subscriber IDs, and some financial account information were potentially accessible. 1,289 California residents were notified starting September 19, 2018. TAG provided 12 months of identity theft protection.
- Massachusetts State AGas victim2018-09-19
The Affiliated Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-09-19. 79 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-09-18
The Affiliated Group (TAG) disclosed a November 2017 phishing incident resulting in unauthorized access to an employee email account. Confirmed on March 28, 2018, the breach exposed PHI and PII including SSNs, driver's licenses, and financial account numbers. TAG engaged forensic investigators, reset credentials, and offered credit monitoring.