MalwareRansomwareData EncryptedRansom DemandedCustomer Data InvolvedPIIIDENTITY_BASICHEALTH_BASICLowContained
Golden Gate Regional Center
bd_32e172bc07baffe0 · schema v1 · pii pii-v1
Full breach record for Golden Gate Regional Center →Golden Gate Regional Center experienced a ransomware incident on September 23, 2020, where an unauthorized actor encrypted files and demanded ransom. The organization detected unusual activity on that date, disabled its network, and engaged forensic investigators. On January 13, 2021, it determined that client information, including names, unique identifiers, service descriptions, and cost information, may have been affected. Notices were sent on March 12, 2021, offering one year of identity monitoring.
California clockDiscovered Sep 23, 2020 → Notified Mar 12, 2021170d ✗ CA 60-day late24 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539079
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 12, 2021
- Raw hash
- 87efb8f37c0ff645eb1dd5f0cc835c37ff91fd4191f6c1b52c19a6df67b9da22
Reporting entity
- Name
- Golden Gate Regional Centernorm: golden gate regional center
- Domain
- ggrc.org
Victim entity
- Name
- Golden Gate Regional Centernorm: golden gate regional center
- Domain
- ggrc.org
Incident
- Discovered
- Sep 23, 2020
- Materiality determined
- —
- Notification sent
- Mar 12, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)
Compliance
- Time to disclose
- 24 weeks(170 days from discovery to filing)
- Compliance flags
- CA 60-day late · 170d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 23, 2020→ Notified: Mar 12, 2021170d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.