Ursus, Inc.
ent_c93a080d10e95313f61d703c
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
174
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Ursus, Inc.
- Normalized
- ursus— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ursusinc.com
Disclosure history (4)newest first
- California State AGas victim2016-09-19
Ursus Holdings, LLC experienced a data breach after employees fell victim to a phishing email with a malicious attachment, leading to compromised credentials. The incident involved potential exposure of PII including SSNs, bank account numbers, and driver's license numbers stored in Google Mail and Docs. The company detected suspicious activity on April 25, 2016, and notified affected individuals on September 15, 2016.
- Montana State AGas victim2016-09-15
Ursus Holdings, LLC notified Montana residents of a security incident discovered on April 25, 2016, where employee email credentials were compromised via phishing. While no customer PII was confirmed accessed, the compromised accounts contained PII including SSNs and financial data. Ursus provided 12 months of credit monitoring and identity repair services.
- Massachusetts State AGas victim2016-09-12
Ursus Holdings LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-09-12. 174 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2016-09-08
Ursus Holdings, LLC notified the NH AG of a phishing incident where an employee's credentials were stolen, leading to unauthorized access to email accounts. Documents containing PII (names, SSNs) and financial data of 42 NH residents were accessed. Ursus isolated accounts, reset passwords, implemented MFA, and planned to offer credit monitoring.