Hartwig Moss Insurance Agency suffered from a data breach that exposed personal info for roughly 1,100 customers.
An investigation revealed an unauthorized outside party gained access through the emails in a phishing attack.
The breach involved basic information, including names, birthdates, and driver’s license numbers, taken from the company’s insurance accounts, according to a news release.
The release said “limited medical information” for a “small number of individuals" may have also been accessed.
It was found that account security was compromised after two employee email accounts were red-flagged for suspicious activity.
TPRM report: https://scoringcyber.rankiteo.com/company/hmia
"id": "har73112323",
"linkid": "hmia",
"type": "Breach",
"date": "03/2019",
"severity": "50",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,100',
'industry': 'Insurance',
'name': 'Hartwig Moss Insurance Agency',
'type': 'Insurance Agency'}],
'attack_vector': 'Phishing',
'data_breach': {'number_of_records_exposed': '1,100',
'personally_identifiable_information': ['Names',
'Birthdates',
'Driver’s License '
'Numbers'],
'type_of_data_compromised': ['Names',
'Birthdates',
'Driver’s License Numbers',
'Limited Medical Information']},
'description': 'Hartwig Moss Insurance Agency suffered from a data breach '
'that exposed personal info for roughly 1,100 customers. An '
'investigation revealed an unauthorized outside party gained '
'access through the emails in a phishing attack. The breach '
'involved basic information, including names, birthdates, and '
'driver’s license numbers, taken from the company’s insurance '
'accounts. The release said “limited medical information” for '
'a “small number of individuals” may have also been accessed. '
'It was found that account security was compromised after two '
'employee email accounts were red-flagged for suspicious '
'activity.',
'impact': {'data_compromised': ['Names',
'Birthdates',
'Driver’s License Numbers',
'Limited Medical Information']},
'initial_access_broker': {'entry_point': 'Email Account Compromise'},
'post_incident_analysis': {'root_causes': 'Phishing Attack'},
'title': 'Data Breach at Hartwig Moss Insurance Agency',
'type': 'Data Breach',
'vulnerability_exploited': 'Email Account Compromise'}