On February 24, 2023, the Maine Office of the Attorney General reported that Aurora Financial Group, Inc. experienced a cybersecurity breach involving unauthorized access by a third-party vendor, Accellion. The breach, which occurred between January 20 and January 22, 2021, affected 3,548 individuals, with 1 resident identified as affected in Maine. The compromised data included financial account numbers, and identity theft protection services were offered through Kroll.
TPRM report: https://www.rankiteo.com/company/aurora-financial-services-inc
"id": "aur845072625",
"linkid": "aurora-financial-services-inc",
"type": "Breach",
"date": "1/2021",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 3548,
'industry': 'Finance',
'name': 'Aurora Financial Group, Inc.',
'type': 'Financial Services'}],
'attack_vector': 'Unauthorized Access',
'data_breach': {'number_of_records_exposed': 3548,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['financial account numbers']},
'date_detected': '2021-01-20',
'date_publicly_disclosed': '2023-02-24',
'description': 'Aurora Financial Group, Inc. experienced a cybersecurity '
'breach involving unauthorized access by a third-party vendor, '
'Accellion. The breach affected 3,548 individuals, with 1 '
'resident identified as affected in Maine. The compromised '
'data included financial account numbers, and identity theft '
'protection services were offered through Kroll.',
'impact': {'data_compromised': ['financial account numbers'],
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'initial_access_broker': {'entry_point': 'Third-party vendor (Accellion)'},
'motivation': 'Unknown',
'references': [{'date_accessed': '2023-02-24',
'source': 'Maine Office of the Attorney General'}],
'response': {'third_party_assistance': ['Kroll']},
'threat_actor': 'Unknown',
'title': 'Aurora Financial Group, Inc. Cybersecurity Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Third-party vendor vulnerability'}