Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSPHIMediumContained
Wurkforce, Inc.
bd_18f0dff354c8b384 · schema v1 · pii pii-v1
Full breach record for Wurkforce, Inc. →Wurkforce, Inc. reported a data breach affecting employee and customer personal information, including SSNs, driver's license numbers, and financial account details. The incident involved unauthorized access to email accounts via phishing between November 22, 2019, and February 12, 2020. Wurkforce engaged forensic investigators, notified law enforcement, enhanced email security, and offered credit monitoring services to affected individuals.
California clockDiscovered Feb 11, 2020 → Notified Aug 3, 2020174d ✗ CA 60-day late25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3a96e56e76927b84Oregon State AGfiled 2020-08-03Candidate
- bd_5304feaf85409776Washington State AGfiled 2020-08-03Verified
- bd_921460ad57981f4cMontana State AGfiled 2020-08-03Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-192693
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 3, 2020
- Raw hash
- 8291bab4169074c66244e62ac4a37d3235b9aedfa2ad5dc29efc4625e34ef3ec
Reporting entity
- Name
- Wurkforce, Inc.norm: wurkforce
Victim entity
- Name
- Wurkforce, Inc.norm: wurkforce
Incident
- Discovered
- Feb 11, 2020
- Materiality determined
- —
- Notification sent
- Aug 3, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 25 weeks(174 days from discovery to filing)
- Compliance flags
- CA 60-day late · 174d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 11, 2020→ Notified: Aug 3, 2020174d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.