HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
Workers' Compensation Insurance Rating Bureau of California
bd_1c5afd8ba3a6c148 · schema v1 · pii pii-v1
Full breach record for Workers' Compensation Insurance Rating Bureau of California →Workers' Compensation Insurance Rating Bureau of California (WCIRB) notified individuals that an unauthorized third party accessed their Box.com system on or about July 9, 2025. The incident involved the acquisition of personal information, including names. WCIRB engaged forensic specialists and is offering identity theft protection services. The breach was contained, and no evidence of misuse was found.
California clockDiscovered Jul 9, 2025 → Notified Dec 10, 2025154d ✗ CA 60-day late22 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_137c95f7177196c3Indiana State AGfiled 2025-10-27(44d gap)Verified
- bd_499f1565cccef01aMaine State AGfiled 2025-10-27(44d gap)Candidate
- bd_c89bebb7fc860ae6Vermont State AGfiled 2025-10-27(44d gap)Verified
- bd_cec940e56ca4e1c4New Hampshire State AGfiled 2025-10-27(44d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 58d gap
- bd_5f2e5ff2174ab56bCalifornia State AGfiled 2025-10-13(58d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-615576
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 10, 2025
- Raw hash
- 3877a70e754f8a51896cce4ba6955d14d727f53563cdf840b1939c013ada419e
Reporting entity
- Name
- Workers' Compensation Insurance Rating Bureau of Californianorm: workers compensation insurance rating bureau of california
Victim entity
- Name
- Workers' Compensation Insurance Rating Bureau of Californianorm: workers compensation insurance rating bureau of california
Incident
- Discovered
- Jul 9, 2025
- Materiality determined
- —
- Notification sent
- Dec 10, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Box.com
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 weeks(154 days from discovery to filing)
- Compliance flags
- CA 60-day late · 154d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 9, 2025→ Notified: Dec 10, 2025154d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.