HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Orange Business Services U.S., Inc.
bd_3177d151dffa0b89 · schema v1 · pii pii-v1
Full breach record for Orange Business Services U.S., Inc. →Orange Business Services U.S., Inc. reported a security incident where an unauthorized individual exploited a vulnerability in a third-party firewall device on January 4, 2022, to access servers containing employee personal information, including names, dates of birth, and Social Security numbers. The breach was discovered on March 17, 2022. Orange Business Services offered affected employees complimentary identity theft protection services.
California clockDiscovered Mar 17, 2022 → Notified Aug 3, 2022139d ✗ CA 60-day late20 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_10d8d178fff3f617Maine State AGfiled 2022-08-03Candidate
- bd_589827cc4fe22218Montana State AGfiled 2022-08-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555934
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 3, 2022
- Raw hash
- 0c6b1a1e6045d64cee0e4a02109ad71cfa5833629955d2e7cf4eae0b9f9b105e
Reporting entity
- Name
- Orange Business Services U.S., Inc.norm: orange business services us
Victim entity
- Name
- Orange Business Services U.S., Inc.norm: orange business services us
Incident
- Discovered
- Mar 17, 2022
- Materiality determined
- —
- Notification sent
- Aug 3, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(139 days from discovery to filing)
- Compliance flags
- CA 60-day late · 139d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 17, 2022→ Notified: Aug 3, 2022139d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.