HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSHighActive
Bayside Community Church
bd_24386c9b4868f9a5 · schema v1 · pii pii-v1
Full breach record for Bayside Community Church →Bayside Covenant Church, Inc. reported a data event in California affecting 1,611 residents. Unauthorized actors accessed employee email accounts between August 3, 2018, and October 20, 2018. The incident exposed personal, government, financial, health, and credential data. The church retained forensic investigators, notified affected individuals, and provided one year of credit monitoring through Kroll.
California clockDiscovered Oct 1, 2018 → Notified Feb 5, 2019127d ✗ CA 60-day late18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,611 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144451
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2019
- Raw hash
- 2665907b0135a7f42310389a7d094adf3e43763924a118a78c47509d63d1ac5e
Reporting entity
- Name
- Bayside Covenant Church, Inc.norm: bayside covenant church
- Domain
- baysideonline.com
Victim entity
- Name
- Bayside Community Churchnorm: bayside community church
- Domain
- baysidechurch.net
Incident
- Discovered
- Oct 1, 2018
- Materiality determined
- —
- Notification sent
- Feb 5, 2019
- Affected individuals
- 1,611
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- CA 60-day late · 127d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 1, 2018→ Notified: Feb 5, 2019127d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.