Social EngineeringPhishingCustomer Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICLowContained
California Cancer Associates for Research and Excellence - Fresno
bd_0bb8e01713467afe · schema v1 · pii pii-v1
Full breach record for California Cancer Associates for Research and Excellence - Fresno →California Cancer Associates for Research and Excellence - Fresno experienced an email phishing incident resulting in unauthorized access to patient information in a small number of email and SharePoint accounts between December 13, 2024, and December 16, 2024. The organization discovered the incident on June 13, 2025. Affected data includes names and other patient information. The organization is providing credit monitoring and additional cybersecurity training to staff.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4dc4e5ab3f70fd16HHS OCRfiled 2025-06-27Verified
- bd_279b9257523008a6California State AGfiled 2025-07-15(18d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-604689
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 27, 2025
- Raw hash
- ff523f8c168c1e98cf4dd16ee6712bc6b7b076a21ad620c99e3a8efaf1c1bad0
Reporting entity
- Name
- California Cancer Associates for Research and Excellence - Fresnonorm: california cancer associates for research and excellence fresno
Victim entity
- Name
- California Cancer Associates for Research and Excellence - Fresnonorm: california cancer associates for research and excellence fresno
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.