Clustered 14 filings across 4 jurisdictions · filing window Jun 6, 2025 → Dec 11, 2025. View entity profile → Other incidents for this victim →
incident inc_a0171f122f7f4dd2 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA MT OR WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
14 filings across 4 jurisdictions · Jun 6, 2025 – Dec 11, 2025 · 3 milestones
Jan 27, 2025 → Feb 6, 2025
When the intrusion reportedly occurred, per the linked filings
Feb 6, 2025
Reported by CALIFORNIA AG, WASHINGTON AG, OREGON AG filings
May 30, 2025
Reported by OREGON AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Episource, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-06-06. The breach occurred during 1/27/2025 - 2/6/2025. The breach was discovered on 5/30/2025. 5,418,866 individuals were affected. Notice was sent on 6/6/2025.
Affected (this filing): 5,418,866
Episource, LLC, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2025-02-06 and filed notice on 2025-06-06. 102,913 Washington residents were affected. 120 days elapsed between awareness and notification. 10 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 102,913
Episource, LLC reported a data breach affecting its computer systems. Unauthorized access occurred between January 27, 2025, and February 6, 2025, when a criminal viewed and copied data. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and other personal data such as driver's license numbers. Episource shut down systems, engaged investigators, and notified law enforcement. Two years of credit monitoring are offered.
Episource, LLC disclosed a data breach affecting its computer systems. Unauthorized access occurred between January 27, 2025, and February 6, 2025, when a criminal viewed and copied data. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and other personal data such as driver's license numbers. Episource engaged forensic investigators, notified law enforcement, and shut down systems. They are offering two years of credit monitoring.
Episource, LLC reported a data breach where an unauthorized third party accessed and copied data from January 27 to February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and potentially Social Security numbers. Episource engaged forensic investigators, notified law enforcement, and shut down systems. They are offering two years of credit monitoring.
Episource, LLC reported a data breach where an unauthorized third party accessed and copied data from its computer systems between January 27, 2025, and February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments, etc.), and in limited instances, Social Security numbers. Episource engaged forensic investigators, notified law enforcement, and shut down systems. It is offering two years of credit monitoring.
Episource, LLC disclosed a data breach affecting patient and member data. Unauthorized access occurred between January 27, 2025, and February 6, 2025, when a criminal actor viewed and copied data including health insurance details, medical records, and Social Security numbers. The incident was discovered on February 6, 2025. Episource shut down systems, engaged forensic investigators, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
Episource, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2025-07-31. The breach occurred from 01/27/2025 to 02/06/2025. 432 Montana residents were affected.
Affected (this filing): 432
Episource, LLC reported unauthorized access to its computer systems between January 27, 2025, and February 6, 2025. The incident involved the exfiltration of protected health information (PHI), including medical records, diagnoses, and treatment data, as well as personal identifiable information (PII) such as names, addresses, and government IDs. Episource detected unusual activity on February 6, 2025, and contained the incident by shutting down systems. Law enforcement was notified. Affected individuals are offered two years of credit monitoring.
Episource, LLC disclosed a data breach affecting health insurance and medical data. Unauthorized access occurred between January 27 and February 6, 2025, and was discovered on February 6, 2025. The attacker viewed and copied data including contact info, health plans, diagnoses, and treatments. Systems were taken offline and law enforcement notified. Credit monitoring offered.
Episource, LLC reported unauthorized access to its computer systems between January 27 and February 6, 2025. An external actor accessed and copied data including contact information, health insurance data, health data (diagnoses, treatments), and other personal data such as Social Security numbers. The incident was discovered on February 6, 2025. Episource engaged forensic investigators, notified law enforcement, and shut down systems. No misuse of data was observed. Credit monitoring was offered.
Episource, LLC reported a data breach where a criminal accessed and copied data from its computer systems between January 27, 2025, and February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments, medical record numbers), date of birth, and in limited instances, Social Security numbers. Episource engaged a forensic team, notified law enforcement, and shut down systems. It is offering two years of credit monitoring.
Episource, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2025-11-12. The breach occurred from 01/27/2025 to 02/06/2025. 1 Montana residents were affected.
Affected (this filing): 1
Episource, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-12-11. The breach occurred during 1/27/2025. The breach was discovered on 2/6/2025. 6,584,876 individuals were affected. Notice was sent on 11/12/2025.
Affected (this filing): 6,584,876