AccidentalMisconfigurationEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumResolved
California Virtual Academies
bd_2771a597781d3fc1 · schema v1 · pii pii-v1
Full breach record for California Virtual Academies →California Virtual Academies (CAVA) notified employees of a data security incident discovered on December 9, 2015. A data security researcher identified a vulnerability in a data storage system. CAVA, with support from vendor K12 Inc., secured the data within hours. Forensic analysis indicated unauthorized access was limited to the researcher who flagged the issue. Social Security numbers and other personal information may have been accessed. CAVA offered 12 months of identity theft protection and credit monitoring.
California clockDiscovered Dec 9, 2015 → Notified Jan 13, 201635d ✓ CA 60-day OK7 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59786
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 25, 2016
- Raw hash
- 47a751b31fe88377392ce24ff31c6baa79689f7cb312357728064d1c0ef6938f
Reporting entity
- Name
- California Virtual Academiesnorm: california virtual academies
- Domain
- cava.k12.com
Victim entity
- Name
- California Virtual Academiesnorm: california virtual academies
- Domain
- cava.k12.com
Incident
- Discovered
- Dec 9, 2015
- Materiality determined
- —
- Notification sent
- Jan 13, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Misconfiguration
- Threat actor
- External
- Third party
- via K12 Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 35d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 9, 2015→ Notified: Jan 13, 201635d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.