HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
City of Tucson, AZ
bd_2bf2cdcf1809778e · schema v1 · pii pii-v1
Full breach record for City of Tucson, AZ →The City of Tucson, Arizona, notified Rhode Island residents of a cybersecurity incident involving unauthorized access to network accounts. Suspicious activity was detected on May 29, 2022, and forensic specialists determined that certain files containing personal information (names, addresses, government IDs) were copied from the City's network. The City offered 3 months of complimentary credit monitoring and identity restoration services through Experian to affected individuals.
California clockDiscovered May 29, 2022 → Notified Sep 29, 2022123d ✗ CA 60-day late18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2f84f901a380587bWashington State AGfiled 2022-09-29Verified
- bd_88191b6f9a91212cMontana State AGfiled 2022-09-29Verified
- bd_a46baffbbf759cc1Maine State AGfiled 2022-09-29Verified
- bd_aab06bc719aecdfcOregon State AGfiled 2022-09-29Verified
Show 1 more filing ↓Show fewer ↑up to 4d gap
- bd_7d660cc84e5dfe06New Hampshire State AGfiled 2022-10-03(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557763
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2022
- Raw hash
- 734c5865a1bd13eeb823cdeb6af4110b858a61a0ff3f9e570790f72a26ab72ec
Reporting entity
- Name
- City of Tucson, AZnorm: city of tucson az
- Industry
- government_public
Victim entity
- Name
- City of Tucson, AZnorm: city of tucson az
- Industry
- government_public
Incident
- Discovered
- May 29, 2022
- Materiality determined
- —
- Notification sent
- Sep 29, 2022
- Affected individuals
- 19
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- CA 60-day late · 123d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 29, 2022→ Notified: Sep 29, 2022123d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.