The California Office of the Attorney General reported a data breach involving American Stock Transfer & Trust Company, LLC on February 16, 2018. The breach occurred on February 1, 2018, when an employee sent Shareholder Information containing names, addresses, social security numbers, and financial account information to 34 financial advisors, inadvertently allowing unauthorized access to all shareholders' information. The number of individuals affected is unknown.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-133853
TPRM report: https://www.rankiteo.com/company/american-stock-transfer-&-trust-company-llc
"id": "ame410072725",
"linkid": "american-stock-transfer-&-trust-company-llc",
"type": "Breach",
"date": "2/2018",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Financial Services',
'location': 'California',
'name': 'American Stock Transfer & Trust Company, LLC',
'type': 'Company'}],
'attack_vector': 'Human Error',
'data_breach': {'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Addresses',
'Social Security Numbers',
'Financial Account Information']},
'date_detected': '2018-02-16',
'date_publicly_disclosed': '2018-02-16',
'description': 'An employee sent Shareholder Information containing names, '
'addresses, social security numbers, and financial account '
'information to 34 financial advisors, inadvertently allowing '
"unauthorized access to all shareholders' information.",
'impact': {'data_compromised': ['Names',
'Addresses',
'Social Security Numbers',
'Financial Account Information']},
'motivation': 'Accidental',
'post_incident_analysis': {'root_causes': 'Human Error'},
'references': [{'date_accessed': '2018-02-16',
'source': 'California Office of the Attorney General'}],
'threat_actor': 'Internal Employee',
'title': 'Data Breach at American Stock Transfer & Trust Company, LLC',
'type': 'Data Breach',
'vulnerability_exploited': 'Unauthorized Access'}