Lion Street Financial, LLC suffered a data breach on January 20, 2021, when unauthorized actors gained access to corporate email accounts. The breach was detected the following day, but its full scope was only disclosed months later, on September 30, 2021. The incident compromised sensitive personal data of 34 Maine residents, including names, Social Security numbers, driver’s license numbers, and medical information highly valuable targets for identity theft and fraud. The breach exposed individuals to significant risks, including financial fraud, medical identity theft, and long-term reputational harm. In response, Lion Street Financial offered affected parties 12 months of credit monitoring and identity protection services via IDX, a remedial measure aimed at mitigating potential damages. However, the delay in public reporting (over eight months) raises concerns about transparency and the company’s incident response protocols. The nature of the stolen data particularly Social Security numbers and medical records suggests a severe impact on victims, as such information can be exploited for years in cybercriminal markets. The breach underscores vulnerabilities in email security and the critical need for robust access controls, especially in sectors handling highly sensitive client data.
TPRM report: https://www.rankiteo.com/company/jrkatz
"id": "jrk021090625",
"linkid": "jrkatz",
"type": "Breach",
"date": "1/2021",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '34 (Maine residents)',
'industry': 'Insurance and Financial Advisory',
'location': 'United States (Maine residents affected)',
'name': 'Lion Street Financial, LLC',
'type': 'Financial Services'}],
'attack_vector': 'Email Account Compromise',
'customer_advisories': '12 months of credit monitoring and identity '
'protection services offered to affected individuals',
'data_breach': {'number_of_records_exposed': '34',
'personally_identifiable_information': ['Names',
'Social Security '
'Numbers',
"Driver's License "
'Numbers'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Medical Information']},
'date_detected': '2021-01-21',
'date_publicly_disclosed': '2021-09-30',
'description': 'The Maine Office of the Attorney General reported that Lion '
'Street Financial, LLC experienced a data breach on January '
'20, 2021, discovered on January 21, 2021, which involved '
'unauthorized access to corporate email accounts. '
'Approximately 34 Maine residents were affected, with types of '
'compromised information including names and combinations of '
"Social Security numbers, driver's license numbers, and "
'medical information. The incident was reported on September '
'30, 2021, and impacted individuals were offered 12 months of '
'credit monitoring and identity protection services through '
'IDX.',
'impact': {'data_compromised': ['Names',
'Social Security Numbers',
"Driver's License Numbers",
'Medical Information'],
'identity_theft_risk': 'High (PII and sensitive data exposed)',
'systems_affected': ['Corporate Email Accounts']},
'references': [{'source': 'Maine Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
'Attorney General'},
'response': {'communication_strategy': 'Notification to affected individuals '
'with offer of 12 months of credit '
'monitoring',
'third_party_assistance': 'IDX (credit monitoring and identity '
'protection services)'},
'title': 'Lion Street Financial, LLC Data Breach (2021)',
'type': 'Data Breach (Unauthorized Access)'}