Extreme Reach, Inc. notified California residents that a phishing email targeted employees on February 8, 2017, resulting in compromised email credentials. The company determined on April 10, 2017, that certain employee email accounts were accessed without authorization. Affected data may include Social Security numbers, driver's license numbers, financial account numbers, credit card numbers, passport numbers, and names. The company engaged forensic investigators and is offering 12 months of credit monitoring through Experian.