DisclosureLens
HackingGovernmentGovernmentData ExfiltratedCustomer Data InvolvedDelayed DiscoveryGovernment IDFinancial accountPHIHealth (basic)MediumContained

Plumas County, California

bd_20faeb4702cb209f · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 23, 2022

Filed

Apr 8, 2022

To disclose

16 days

Affected

Not disclosed

Confidence

65%

Plumas County, California notified residents that an unauthorized party accessed IT systems from October 20 to November 14, 2021, and acquired files containing SSNs, driver's license numbers, financial account info, and medical/health insurance data. The County first learned of the incident on March 23, 2022, when technical issues disrupted operations. The County secured systems, launched an investigation, notified law enforcement, and offered one year of Experian IdentityWorks credit monitoring.

Leak gap clock Leak >90d16 days discovery → filing

Incident timeline

undetected · 154 days
discovery → filing · 16 days

Oct 20, 2021

Begins

Mar 23, 2022

Discovered

Apr 8, 2022

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.