MisuseData MishandlingEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Rakuten Americas
bd_3174790e2060a4d9 · schema v1 · pii pii-v1
Full breach record for Rakuten Americas →Rakuten USA, Inc. (DBA Rakuten Americas) notified the California Attorney General of a data breach involving an employee who transferred files containing sensitive personal information (name, SSN, date of birth) of other employees to a personal device while voluntarily leaving the company. The incident was detected on January 21, 2021. The company deleted the files from the personal device, contacted law enforcement, and offered credit monitoring to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d667a4564196f04aMaine State AGfiled 2021-02-11Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537958
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2021
- Raw hash
- 29f9ddf62a0a22e7fc4761484afbf8dd517fc149d7a87ae7e4cc20748ca9d8dc
Reporting entity
- Name
- Rakuten Americasnorm: rakuten americas
Victim entity
- Name
- Rakuten Americasnorm: rakuten americas
Incident
- Discovered
- Jan 21, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Regulator citations
- Providing notice to appropriate regulatory authorities
- Initial access
- insider_action
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.