Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
California Community Colleges Chancellor's Office (submitted c/o Pearson VUE)
bd_173a764261b0098f · schema v1 · pii pii-v1
Full breach record for California Community Colleges Chancellor's Office (submitted c/o Pearson VUE) →Pearson VUE, a service provider for the California Community Colleges Chancellor's Office, discovered that California Nurses' Aide information may have been improperly forwarded to an unauthorized account due to email phishing between October 2016 and September 2017. Affected data may include name, Social Security number, date of birth, and exam score information. The unauthorized account was blocked, and additional safeguards were implemented. Complimentary two-year Experian IdentityWorks membership is offered.
California clockDiscovered Oct 1, 2016 → Notified Aug 1, 2018669d ✗ CA 60-day late31 months discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-146256
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 12, 2019
- Raw hash
- aeb0cd96293ec409a119ee24de669a24e2f177af32ee462338d6d054464073f7
Reporting entity
- Name
- California Community Colleges Chancellor's Office (submitted c/o Pearson VUE)norm: california community colleges chancellor s office submitted c o pearson vue
Victim entity
- Name
- California Community Colleges Chancellor's Office (submitted c/o Pearson VUE)norm: california community colleges chancellor s office submitted c o pearson vue
Incident
- Discovered
- Oct 1, 2016
- Materiality determined
- —
- Notification sent
- Aug 1, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Third party
- via Pearson VUE
- Initial access
- phishing_link
Compliance
- Time to disclose
- 31 months(923 days from discovery to filing)
- Compliance flags
- CA 60-day late · 669d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 1, 2016→ Notified: Aug 1, 2018669d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.