County of Los Angeles Department of Mental Health
bd_0450a32caae6280c · schema v1 · pii pii-v1
Full breach record for County of Los Angeles Department of Mental Health →Los Angeles County Department of Mental Health notified individuals that their personal information may have been accessed following a cyberattack on the City of Gardena Police Department on January 22, 2024. Threat actors exploited a multi-factor authentication vulnerability (push notification spam) to access a GPD employee's Microsoft Office 365 account, then used email exchanges to compromise a DMH employee's account. Affected data includes names, dates of birth, SSNs, addresses, phone numbers, and medical record numbers. No evidence of misuse was found. DMH disabled accounts, reset credentials, engaged forensic specialists, and notified Microsoft.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5770a98a6f25f686HHS OCRfiled 2024-03-22Verified
- bd_8cf4b12b3cb8239eCalifornia State AGfiled 2024-05-17(56d gap)Verified
- bd_d9847fc4e0964718HHS OCRfiled 2024-05-20(59d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582905
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2024
- Raw hash
- 8d4c887079ca156bda2c5ffd22b8866ee6118a19e4d219a87361b13666d39138
Reporting entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Victim entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Incident
- Discovered
- Jan 22, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Third party
- via City of Gardena Police Department
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.