Social EngineeringPhishingStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedMulti-Stage ChainTargetedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
South Carolina Department of Revenue
bd_2336edadee3e8252 · schema v1 · pii pii-v1
Full breach record for South Carolina Department of Revenue →South Carolina Department of Revenue suffered a data breach in September 2012, discovered in October 2012. Attackers used a phishing email to steal credentials, accessed systems via Citrix, and exfiltrated encrypted tax data including SSNs and financial info. Mandiant conducted forensic investigation. Remediation included containment and credit monitoring for affected taxpayers.
California clockDiscovered Oct 10, 2012 → Notified Dec 10, 201261d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-37162
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 10, 2012
- Raw hash
- 84855e7a81a9ee34bd5bee8b75df55e2e9b2644be18e81e517a65a44b92a6225
Reporting entity
- Name
- South Carolina Department of Revenuenorm: south carolina department of revenue
- Industry
- government_public
Victim entity
- Name
- South Carolina Department of Revenuenorm: south carolina department of revenue
- Industry
- government_public
Incident
- Discovered
- Oct 10, 2012
- Materiality determined
- —
- Notification sent
- Dec 10, 2012
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1078.004 Cloud AccountsT1119 Automated CollectionT1074 Data StagedT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified South Carolina Attorney General (via SB24 submission)
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- CA 60-day late · 61d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 10, 2012→ Notified: Dec 10, 201261d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.