HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
City of Oxnard
bd_240da938e40b2af8 · schema v1 · pii pii-v1
Full breach record for City of Oxnard →The City of Thousand Oaks notified residents of a data breach involving its third-party payment processing vendor. Between November 21, 2017, and February 26, 2018, an unauthorized individual accessed the vendor's computer, potentially exposing customer names, payment card numbers, and expiration dates. The City engaged forensic investigators and enhanced security protocols.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136764
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 4, 2018
- Raw hash
- 7da4d00b105d0c1e2b7d0ea2fac87657d4ccdee89545b54c5b5db3a80375a2e3
Reporting entity
- Name
- City of Oxnardnorm: city of oxnard
Victim entity
- Name
- City of Oxnardnorm: city of oxnard
Incident
- Discovered
- Feb 28, 2018
- Materiality determined
- Nov 21, 2017
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(96 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.