DisclosureLens
HackingTelecom & MediaInformationStolen CredentialsCustomer Data InvolvedCredentialsIdentity (basic)MediumActive

TengoInternet

bd_064dcaed316bb30e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 23, 2018

Filed

Oct 26, 2018

To disclose

5 weeks

Affected

59,835state residents only

Confidence

66%
Full breach record for TengoInternet

TengoInternet, Inc. notified the California AG of unauthorized access to a consumer database containing usernames, passwords, names, and email addresses. The incident was discovered on September 23, 2018, with access occurring in or prior to April 2018. Approximately 59,835 California residents were affected. The company engaged forensic investigators, notified the FBI, disabled inactive accounts, and forced password resets. The investigation was ongoing at the time of notification.

California clockDiscovered Sep 23, 2018Notified Oct 26, 201833d CA 60-day OK5 weeks discovery → filing

Incident timeline

undetected · 175 days
discovery → filing · 5 weeks / 33 days

Apr 1, 2018

Begins

Sep 23, 2018

Discovered

Oct 26, 2018

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed59,835 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.