HackingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Plumas County, CA - Official Website
bd_20faeb4702cb209f · schema v1 · pii pii-v1
Full breach record for Plumas County, CA - Official Website →Plumas County, California, notified individuals of a data breach occurring between October 20, 2021, and November 14, 2021. An unauthorized party accessed IT systems and acquired files containing Social Security numbers, driver's license numbers, financial account information, and medical/health insurance data. The County secured systems, launched an investigation, notified law enforcement, and offered one year of Experian IdentityWorks.
Leak gap clock⏱ Leak >90d16 days discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
A leak claim by lockbit2 about this victim predates this filing by 152 days.View originating leak claim
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552399
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2022
- Raw hash
- be186b15e55aed69dccb21a782b81f6a1701c19aef29334a228702ed15a5b6fc
Reporting entity
- Name
- Plumas County, CA - Official Websitenorm: plumas county ca official website
- Domain
- plumascounty.us
Victim entity
- Name
- Plumas County, CA - Official Websitenorm: plumas county ca official website
- Domain
- plumascounty.us
Incident
- Discovered
- Mar 23, 2022
- Materiality determined
- —
- Notification sent
- Mar 23, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- Leak >90dCA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 23, 2022→ Notified: Mar 23, 20220d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.