Social EngineeringPhishingEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALMediumContained
City College of San Francisco
bd_351801881dc696ac · schema v1 · pii pii-v1
Full breach record for City College of San Francisco →City College of San Francisco notified the California Attorney General of a data breach discovered on April 15, 2016. An employee responded to a phishing email, leading to unauthorized access to their email account. The compromised emails contained student information, including names, addresses, Social Security numbers, and financial aid application data. The college secured the account, reset passwords, and offered one year of identity protection services to affected individuals. Additional employee training and authentication enhancements were planned.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-61821
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 13, 2016
- Raw hash
- d9924e472a7cd777fc8134ee9e67de1361ac0d5b626699efb345c10de52f642c
Reporting entity
- Name
- City College of San Francisconorm: city college of san francisco
- Domain
- ccsf.community.highbond.com
Victim entity
- Name
- City College of San Francisconorm: city college of san francisco
- Domain
- ccsf.community.highbond.com
Incident
- Discovered
- Apr 15, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.