HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
North Carolina Board of Physical Therapy Examiners
bd_2d43c3964e333e17 · schema v1 · pii pii-v1
Full breach record for North Carolina Board of Physical Therapy Examiners →The North Carolina Board of Physical Therapy Examiners experienced a data breach where an unauthorized individual accessed a computer containing names, addresses, dates of birth, and Social Security numbers. The incident occurred between June 3, 2022, and was confirmed on July 22, 2022. The Board engaged forensic experts, notified law enforcement, and offered identity theft protection services to affected individuals.
California clockDiscovered Jul 22, 2022 → Notified Sep 2, 202242d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0d3a10e1c5d6ecc0Maine State AGfiled 2022-09-02Candidate
- bd_b52e0f415bd267aeMontana State AGfiled 2022-09-02Candidate
- bd_8e7d37ecff705b0fNew Hampshire State AGfiled 2022-09-06(4d gap)Verified
- bd_ccb05409b99f5e55South Carolina State AGfiled 2022-09-06(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556882
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 2, 2022
- Raw hash
- d890b8388930216351f8180a955ebb8fd2526c23c46715bb8dd26e949202263c
Reporting entity
- Name
- North Carolina Board of Physical Therapy Examinersnorm: north carolina board of physical therapy examiners
Victim entity
- Name
- North Carolina Board of Physical Therapy Examinersnorm: north carolina board of physical therapy examiners
Incident
- Discovered
- Jul 22, 2022
- Materiality determined
- —
- Notification sent
- Sep 2, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported this incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 42d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 22, 2022→ Notified: Sep 2, 202242d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.