CSIDB logo
Incident

Association of National Advertisers

Incident posture

Attack window
Oct 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-28 00:00

Linked entities

Victim
Association of National Advertisers
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Association of National Advertisers experienced a phishing attack that potentially compromised employee data, including names and Social Security numbers. The organization detected unauthorized access during an investigation into the incident, which may have resulted in the theft of sensitive personal information affecting current and former staff members.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Association of National Advertisers (ANA) experienced a phishing attack that compromised employee data, as disclosed in a January 24, 2019 letter to former employees. The organization first detected a "possible data security incident" in October 2018, though the exact date of initial compromise remains unspecified in available records. The attack vector involved phishing techniques, though technical specifics regarding the phishing mechanism (such as email content or targeted systems) were not detailed in public disclosures. The incident potentially resulted in unauthorized access to sensitive personally identifiable information (PII) belonging to current and former ANA personnel.

In its January 2019 notification, the ANA confirmed that exposed data included employee names and Social Security numbers, indicating theft of highly sensitive information. The organization did not publicly quantify the number of affected individuals beyond acknowledging impacted "employees" and "former employees." No evidence suggested member organization data or advertiser information was compromised. The breach timeline shows a three-month gap between incident detection (October 2018) and victim notification (January 2019), though the reasons for this delay were not explained in source materials. The ANA's response included direct written notification to former staff but did not disclose whether credit monitoring services or other remediation measures were offered. No subsequent reports confirmed fraudulent use of the stolen data or detailed containment actions taken by the organization.

Sources

Sources available to members: 1 source.

CSIDB