California Virtual Academies
bd_2771a597781d3fc1 · schema v1 · pii pii-v1
Full breach record for California Virtual Academies →California Virtual Academies (CAVA) notified employees of a data security incident discovered on December 9, 2015. A data security researcher identified a vulnerability in a data storage system. CAVA, with support from vendor K12 Inc., secured the data within hours. Forensic analysis indicated unauthorized access was limited to the researcher who flagged the issue. Social Security numbers and other personal information may have been accessed. CAVA offered 12 months of identity theft protection and credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 9, 2015
Begins
Dec 9, 2015
Discovered
Jan 25, 2016
Filed
vs. sector median
3 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.