Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNTEDUCATIONMediumContained
County of Los Angeles Department of Mental Health
bd_1f2f89a6c37be2dc · schema v1 · pii pii-v1
Full breach record for County of Los Angeles Department of Mental Health →Los Angeles County Department of Mental Health experienced a phishing incident on October 19, 2021, where three employee email accounts were compromised via malicious links. The incident potentially exposed personal information including names, addresses, SSNs, driver's licenses, medical/health information, and financial account numbers. The organization notified law enforcement, reset credentials, and deployed additional security measures. Notification was delayed at the request of law enforcement.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a7d22247c37f34fbHHS OCRfiled 2022-04-20Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552740
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2022
- Raw hash
- 2777558d6be0e06463c6f7dc4d1e2234d59f4d68cc21c3e24d4067853cf9270c
Reporting entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Victim entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Incident
- Discovered
- Oct 19, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNTEDUCATION
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified law enforcement authoritiesReporting this incident to the U.S. Department of Health & Human Services Office of Civil Rights
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 weeks(183 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.