Cedar Falls Utilities
bd_2398484eb6a8adbf · schema v1 · pii pii-v1
Full breach record for Cedar Falls Utilities →Cedar Falls Utilities notified customers of a data breach involving a security vulnerability on a third-party maintained website. The incident potentially exposed names, addresses, Social Security numbers, and driver's license numbers of customers who used an online form between 2015 and 2020. The vulnerability was fixed within two hours of discovery on August 14, 2020. CFU offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2015
Begins
Aug 14, 2020
Discovered
Oct 14, 2020
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_9ad21e29c689a4702020-09-14 · +30dCandidate
- Indiana State AGbd_f34229b7ce4cbc472020-09-14 · +30dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 14 (MA), last Oct 14 (MT) — a 30-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.