Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
County of Los Angeles
bd_22dc50bf9a61f922 · schema v1 · pii pii-v1
Full breach record for County of Los Angeles →On May 13, 2016, the County of Los Angeles experienced a phishing email attack affecting approximately 108 employee email accounts. The attack potentially compromised personally identifiable information (PII) and protected health information (PHI) of service recipients, including names, SSNs, driver's license numbers, payment card info, bank account info, and medical records. The County notified law enforcement and relevant regulators (CDPH, CA AG, HHS OCR). Free identity monitoring was offered to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed108 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65499
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2016
- Raw hash
- bd0de2a8e40c0d32df2a07d99e0a582b9b865f4df7344750e86ba6c1ae8e196d
Reporting entity
- Name
- County of Los Angelesnorm: county of los angeles
Victim entity
- Name
- County of Los Angelesnorm: county of los angeles
Incident
- Discovered
- May 13, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 108
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified the California Department of Public HealthNotified the State Attorney General’s OfficeNotified the U.S. Department of Health & Human Services’ Office for Civil Rights
- Initial access
- phishing_link
Compliance
- Time to disclose
- 31 weeks(217 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.