HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
Kaplan North America, LLC
bd_1e887c69b831ca2b · schema v1 · pii pii-v1
Full breach record for Kaplan North America, LLC →Kaplan North America, LLC identified unauthorized access to its computer servers between October 30 and November 18, 2025. An external actor accessed files containing names, Social Security numbers, and/or driver's license numbers. The breach was reported to the California AG on March 17, 2026. Affected individuals were offered complimentary Experian IdentityWorks credit monitoring for 12 months.
California clockConsumers notified Mar 17, 2026 → AG copy submitted Mar 17, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_03ac6b2ac5b6d4a6Indiana State AGfiled 2026-03-17Candidate
- bd_3af6a5c8e815660bMaine State AGfiled 2026-03-17Verified
- bd_43bbc55f2a1fdb41South Carolina State AGfiled 2026-03-17Verified
- bd_5195761b433bf377New Hampshire State AGfiled 2026-03-17Verified
Show 6 more filings ↓Show fewer ↑up to 1d gap
- bd_6cd40678378733bbIowa State AGfiled 2026-03-17Verified
- bd_7eccbae29faca690Washington State AGfiled 2026-03-17Verified
- bd_9cd5c500ae4a6563Delaware State AGfiled 2026-03-17Verified
- bd_a1a2590136ab7eddVermont State AGfiled 2026-03-17Verified
- bd_dde3052cb27cb9c5Oregon State AGfiled 2026-03-17Verified
- bd_2163f3082d7a92d9Texas State AGfiled 2026-03-18(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-620355
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2026
- Raw hash
- 6c09ddd168e543541f9148f491f4fd996b7c8c192290814c855c3e4653d06ca5
Reporting entity
- Name
- Kaplan North America, LLCnorm: kaplan north america
- Domain
- kaplan.com
Victim entity
- Name
- Kaplan North America, LLCnorm: kaplan north america
- Domain
- kaplan.com
Incident
- Discovered
- —
- Materiality determined
- Feb 21, 2026
- Notification sent
- Mar 17, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified California Attorney General
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Mar 17, 2026→ AG copy submitted: Mar 17, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.