HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
GardaWorld Cash U.S.
bd_2688209c79606e8b · schema v1 · pii pii-v1
Full breach record for GardaWorld Cash U.S. →GardaWorld Cash U.S. disclosed a cybersecurity incident where an unauthorized actor accessed administrative files on facility systems in Florida between October 30 and November 16, 2023. The actor copied some files on November 16, 2023. Affected data may include names, Social Security numbers, Driver’s License numbers, dates of birth, and health-related information. The company engaged external cybersecurity experts, secured systems, and offered two years of identity monitoring to affected individuals.
California clockDiscovered Nov 16, 2023 → Notified Mar 15, 2024120d ✗ CA 60-day late18 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_0e1b21509eb07ef5Maine State AGfiled 2024-03-22Candidate
- bd_518b38cdfe9dac68Delaware State AGfiled 2024-03-22Verified
- bd_740aa781d9cce1fdVermont State AGfiled 2024-03-22Verified
- bd_7416629fa1a9cccaOregon State AGfiled 2024-03-22Verified
Show 4 more filings ↓Show fewer ↑
- bd_ad65ae76f4ee4ad3Washington State AGfiled 2024-03-22Verified
- bd_b0ebb9df09562ad9Delaware State AGfiled 2024-03-22Verified
- bd_bb072a3fa48d3523Indiana State AGfiled 2024-03-22Verified
- bd_fe76d026e22de983Montana State AGfiled 2024-03-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582908
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2024
- Raw hash
- 41af05e1ccd4f848f2ce289a410588003a9fa3d6a6f2b43d193770b48944d3c1
Reporting entity
- Name
- GardaWorld Cash U.S.norm: gardaworld cash us
Victim entity
- Name
- GardaWorld Cash U.S.norm: gardaworld cash us
Incident
- Discovered
- Nov 16, 2023
- Materiality determined
- —
- Notification sent
- Mar 15, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- CA 60-day late · 120d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 16, 2023→ Notified: Mar 15, 2024120d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.