HackingEmployee Data InvolvedCREDENTIALSLowContained
Bank of the West
bd_2da3bfcafcf75366 · schema v1 · pii pii-v1
Full breach record for Bank of the West →Bank of the West discovered on December 19, 2013, that a retired internet job application server had been illegally accessed. Unauthorized users may have obtained user names and passwords created to access the site. The bank secured the servers, established additional security measures, and cooperated with law enforcement. Affected individuals were offered one year of free identity monitoring.
California clockDiscovered Dec 19, 2013 → Notified Feb 6, 201449d ✓ CA 60-day OK7 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-44030
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2014
- Raw hash
- 56b30dd2e4628a9b13d6d858d527187881cb6d70d6ad1a192e7085e0d4d1e797
Reporting entity
- Name
- Bank of the Westnorm: bank of the west
Victim entity
- Name
- Bank of the Westnorm: bank of the west
Incident
- Discovered
- Dec 19, 2013
- Materiality determined
- —
- Notification sent
- Feb 6, 2014
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 49d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 19, 2013→ Notified: Feb 6, 201449d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.