Ethos Technologies Inc
ent_8e6109134c166c36e2974904
Disclosures
12
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
33,985
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Ethos Technologies Inc
- Normalized
- ethos technologies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001788451
- Domain
- None on record
Disclosure history (12)newest first
- California State AGas victim2023-10-04
Ethos Technologies Inc. disclosed a cyberattack where unauthorized actors exploited its online life insurance application process to access Social Security numbers. The incident occurred between August 4, 2022, and December 9, 2022, but was not discovered until December 8, 2022. Actors used known personal information to trigger a third-party service that returned SSNs in page source code, which were then extracted. Ethos notified the FBI, engaged forensic investigators, and implemented technical code changes. Affected individuals were offered two years of credit monitoring and identity theft protection.
- Montana State AGas victim2022-12-21
Ethos Technologies Inc notified Montana residents of a cyberattack where unauthorized actors used stolen personal information (name, DOB, address) obtained from other sources to access Social Security numbers via the company's online insurance application flow. The incident occurred between August 4 and December 9, 2022. Ethos notified the FBI, engaged forensic investigators, and provided two years of credit monitoring.
- Massachusetts State AGas victim2022-12-21
Ethos Technologies Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-12-21. 1,114 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2022-12-21
Ethos Technologies Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-08-04 and was reported on 2022-12-21. 521 Indiana residents were affected. 33,985 individuals affected in total.
- California State AGas victim2022-12-21
Ethos Technologies Inc. disclosed a cyberattack where unauthorized actors exploited its online insurance application process to access Social Security numbers. The incident occurred between August 4, 2022, and December 9, 2022, and was discovered on December 8, 2022. Actors used previously obtained personal information (name, DOB, address) to trigger SSN disclosure via a third-party integrated service, then extracted the data from page source code. Ethos notified the FBI, engaged forensic investigators, and implemented technical fixes. Affected individuals are offered credit monitoring.
- Oregon State AGas victim2022-12-21
Ethos Technologies Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-12-21. The breach occurred during 8/4/2022 - 12/9/2022. The breach was discovered on 12/8/2022. 33,985 individuals were affected. Notice was sent on 12/21/2022.
- Maine State AGas victim2022-12-21
Ethos Technologies Inc. experienced a data breach through the exploitation of its online insurance application flow, resulting in the acquisition of names and Social Security numbers. The breach was discovered on December 8, 2022, and occurred on August 4, 2022. The company notified affected individuals and offered 24 months of identity theft and credit monitoring services through Experian.
- Washington State AGas victim2022-12-20
Ethos Technologies Inc. disclosed a cyberattack where unauthorized actors used stolen personal data (name, DOB, address) obtained from other sources to access SSNs via the company's online insurance application. The incident occurred between August 4 and December 9, 2022. Ethos notified the FBI, engaged forensic investigators, and offered credit monitoring.
- Massachusetts State AGas victim2022-02-14
Ethos Technologies Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-02-14. 354 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-02-11
Ethos Technologies Inc. reported a data breach affecting 13 Maine residents. The breach occurred between July 15, 2021, and January 12, 2022, and was discovered on January 12, 2022. Unauthorized actors launched a sophisticated attack against the company's online insurance application flow. Using information obtained from other sources (name, address, date of birth, and driver's license state), the actors utilized specialized web tools to access corresponding driver's license numbers from the page source code. The company offered 24 months of identity theft and credit monitoring services to affected individuals.
- Indiana State AGas victim2022-02-11
Ethos Technologies, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-07-15 and was reported on 2022-02-11. 56 Indiana residents were affected. 13,300 individuals affected in total.
- California State AGas victim2022-02-11
Ethos Technologies Inc. reported a data breach to the California Attorney General's Office. The incident involved a phishing attack on January 12, 2022, which compromised customer records including names, Social Security numbers, dates of birth, driver's license numbers, and financial account numbers. The breach occurred on July 15, 2021. The company engaged forensic investigators and law enforcement (FBI and CA DOJ). Affected individuals were offered two years of credit monitoring and identity theft protection services.