Ethos Technologies Inc
ent_8e6109134c166c36e2974904
Disclosures
7
State AG · 4 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
33,985
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Ethos Technologies Inc
- Normalized
- ethos technologies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🐻California State AGas victim2023-10-04
Ethos Technologies Inc. disclosed a cyberattack where unauthorized actors exploited its online life insurance application process to access Social Security numbers. The incident occurred between August 4, 2022, and December 9, 2022, but was not discovered until December 8, 2022. Actors used known personal information to trigger a third-party service that returned SSNs in page source code, which were then extracted. Ethos notified the FBI, engaged forensic investigators, and implemented technical code changes. Affected individuals were offered two years of credit monitoring and identity theft protection.
- 🦬Montana State AGas victim2022-12-21
Ethos Technologies Inc reported a data breach to the Montana Attorney General. The breach was reported on 2022-12-21. The breach occurred from 8/4/2022 to 12/9/2022. 68 Montana residents were affected.
- 🐻California State AGas victim2022-12-21
Ethos Technologies Inc. reported a data breach affecting Social Security numbers. Attackers used stolen credentials obtained via phishing to access an online insurance application flow, causing a third-party service to return SSNs in the page source code. The incident spanned August 4, 2022, to December 9, 2022. Ethos notified the FBI, engaged forensic investigators, and offered credit monitoring.
- 🦫Oregon State AGas victim2022-12-21
Ethos Technologies Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-12-21. The breach occurred during 8/4/2022 - 12/9/2022. The breach was discovered on 12/8/2022. 33,985 individuals were affected. Notice was sent on 12/21/2022.
- 🦞Maine State AGas victim2022-12-21
Ethos Technologies Inc. experienced a data breach through the exploitation of its online insurance application flow, resulting in the acquisition of names and Social Security numbers. The breach was discovered on December 8, 2022, and occurred on August 4, 2022. The company notified affected individuals and offered 24 months of identity theft and credit monitoring services through Experian.
- 🦞Maine State AGas victim2022-02-11
Ethos Technologies Inc. reported a data breach affecting 13 Maine residents. The breach occurred between July 15, 2021, and January 12, 2022, and was discovered on January 12, 2022. Unauthorized actors launched a sophisticated attack against the company's online insurance application flow. Using information obtained from other sources (name, address, date of birth, and driver's license state), the actors utilized specialized web tools to access corresponding driver's license numbers from the page source code. The company offered 24 months of identity theft and credit monitoring services to affected individuals.
- 🐻California State AGas victim2022-02-11
Ethos Technologies Inc., an online life insurance provider, discovered on January 12, 2022 that unauthorized actors had exploited a feature in its online insurance application flow to access driver's license numbers. Attackers used pre-obtained personal information (name, DOB, address, license state) to trigger a third-party validation service, then extracted license numbers from website page source code. The unauthorized activity spanned approximately July 15, 2021 through January 12, 2022. Ethos notified federal law enforcement, made technical changes, and engaged a forensic firm.