DisclosureLens
AccidentalEducationEducationMisconfigurationEmployee Data InvolvedGovernment IDIdentity (basic)MediumResolved

California Virtual Academies

bd_2771a597781d3fc1 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 9, 2015

Filed

Jan 25, 2016

To disclose

7 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for California Virtual Academies

California Virtual Academies (CAVA) notified employees of a data security incident discovered on December 9, 2015. A data security researcher identified a vulnerability in a data storage system. CAVA, with support from vendor K12 Inc., secured the data within hours. Forensic analysis indicated unauthorized access was limited to the researcher who flagged the issue. Social Security numbers and other personal information may have been accessed. CAVA offered 12 months of identity theft protection and credit monitoring.

California clockDiscovered Dec 9, 2015Notified Jan 13, 201635d CA 60-day OK7 weeks discovery → filing

Incident timeline

discovery → filing · 7 weeks / 47 days

Dec 9, 2015

Begins

Dec 9, 2015

Discovered

Jan 25, 2016

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.