HackingData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
USA Waste Management
bd_17830c845d3f6151 · schema v1 · pii pii-v1
Full breach record for USA Waste Management →USA Waste-Management Resources, LLC notified individuals that an unauthorized actor entered their network between January 21 and 23, 2021, accessing and taking a limited number of files. The company discovered suspicious activity on January 21, 2021. Affected data may include names, Social Security numbers, dates of birth, and driver's license numbers of employees, former employees, or dependents. The investigation remains ongoing. The company engaged third-party forensic specialists, contacted the FBI, and is offering 12 months of credit monitoring through Experian.
California clockDiscovered Jan 21, 2021 → Notified May 28, 2021127d ✗ CA 60-day late18 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_12d04e1778d548ffWashington State AGfiled 2021-05-28Candidate
- bd_188fbd870cd7a42eMontana State AGfiled 2021-05-28Verified
- bd_5c94835b6d910262Maine State AGfiled 2021-05-28Verified
- bd_683fe95cf33b77c1Delaware State AGfiled 2021-05-28Verified
Show 2 more filings ↓Show fewer ↑
- bd_6bc9df8ba881f06cSouth Carolina State AGfiled 2021-05-28Verified
- bd_d7982d7a65b49284Oregon State AGfiled 2021-05-28Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541404
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 28, 2021
- Raw hash
- fd104dc80b9098fe94752a5e29173f2a34d0265deebecdfff8e64051472a3cef
Reporting entity
- Name
- USA Waste Managementnorm: usa waste management
- Domain
- usawastemanagement.com
Victim entity
- Name
- USA Waste Managementnorm: usa waste management
- Domain
- usawastemanagement.com
Incident
- Discovered
- Jan 21, 2021
- Materiality determined
- —
- Notification sent
- May 28, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Contacted the FBI
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- CA 60-day late · 127d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 21, 2021→ Notified: May 28, 2021127d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.