CPT Group, Inc. notified California regulators of a phishing incident where an employee's email account was accessed by an unauthorized individual from November 22, 2017, through December 8, 2017. The breach potentially exposed the names, addresses, and Social Security numbers of class members from a settlement. CPT implemented multi-factor authentication, retrained employees, and provided one year of complimentary identity monitoring through Kroll.