HackingStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
City of Bakersfield
bd_375a81e6fe64e445 · schema v1 · pii pii-v1
Full breach record for City of Bakersfield →The City of Bakersfield experienced a data breach involving its Click2Gov online payment system, developed by third-party vendor CentralSquare Technologies. Between July 30, 2019, and September 5, 2019, an unauthorized party inserted malicious code to capture payment card data (including CVV) and personal information. The City removed the code, engaged forensic investigators, notified law enforcement, and terminated its contract with the vendor.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-183190
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 4, 2019
- Raw hash
- 179eff1944dcac3f120d883acaca140a8c3037024ea1d6ea42323f23688c9693
Reporting entity
- Name
- City of Bakersfieldnorm: city of bakersfield
Victim entity
- Name
- City of Bakersfieldnorm: city of bakersfield
Incident
- Discovered
- Sep 5, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.