DisclosureLens
HackingGovernmentGovernmentStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Financial accountLowContained

City of Thousand Oaks

bd_240da938e40b2af8 · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 28, 2018

Filed

Jun 4, 2018

To disclose

14 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for City of Thousand Oaks2 incidents on file

The City of Thousand Oaks notified residents that an unauthorized individual may have accessed a vendor's computer processing credit card transactions. The incident occurred between November 21, 2017, and February 26, 2018, and was discovered on February 28, 2018. Affected data may include names, payment card numbers, and expiration dates. The City hired a forensic firm and is enhancing security protocols.

Incident timeline

undetected · 99 days
discovery → filing · 14 weeks / 96 days

Nov 21, 2017

Begins

Feb 28, 2018

Discovered

Jun 4, 2018

Filed

vs. sector median

+3 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.