Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICLowContained
Mojave Radiation Oncology Medical Group
bd_2984c6e903c2cd3c · schema v1 · pii pii-v1
Full breach record for Mojave Radiation Oncology Medical Group →Mojave Radiation Oncology Medical Group experienced an email phishing incident resulting in unauthorized access to patient information in a small number of email and SharePoint accounts between December 13-16, 2024. The organization discovered the incident on June 13, 2025. Affected data includes names and potentially other patient health information. The organization is providing credit monitoring and additional cybersecurity training to staff.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605498
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2025
- Raw hash
- 9a04df948b9b17694ec6fbfe51ac4eb86e94a34437f4f08e235424bc835f17eb
Reporting entity
- Name
- Mojave Radiation Oncology Medical Groupnorm: mojave radiation oncology medical
Victim entity
- Name
- Mojave Radiation Oncology Medical Groupnorm: mojave radiation oncology medical
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.