Social EngineeringPhishingEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTEMPLOYMENTMediumContained
Centinela Valley Union High School District
bd_05e3911740758392 · schema v1 · pii pii-v1
Full breach record for Centinela Valley Union High School District →Centinela Valley Union High School District experienced a phishing incident on January 31, 2019, where an employee received a fraudulent email. An unauthorized individual may have obtained W-2 information for employees, including names, addresses, Social Security numbers, and 2018 wage information. The district notified the IRS, state tax boards, and federal law enforcement. Affected employees were offered one year of Experian IdentityWorks identity protection services.
California clockDiscovered Jan 31, 2019 → Notified Jan 31, 20190d ✓ CA 60-day OK19 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144854
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2019
- Raw hash
- f7a767e1fa795ef20a6266ec85ddfa1265cfe1cc8e2f1dc2f3a3ace284cc5150
Reporting entity
- Name
- Centinela Valley Union High School Districtnorm: centinela valley union high school district
Victim entity
- Name
- Centinela Valley Union High School Districtnorm: centinela valley union high school district
Incident
- Discovered
- Jan 31, 2019
- Materiality determined
- —
- Notification sent
- Jan 31, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified the IRSNotified state tax boardsNotified federal law enforcement authorities
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 days(19 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 31, 2019→ Notified: Jan 31, 20190d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.