HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumResolved
City of Sebastopol
bd_38f0c678d4927412 · schema v1 · pii pii-v1
Full breach record for City of Sebastopol →The City of Sebastopol notified affected individuals of a data breach involving unauthorized access to an employee's email account between April 28 and May 11, 2021. The incident exposed names, SSNs, driver's license numbers, financial account info, and/or health information. The City engaged a cybersecurity firm, secured the account, and offered one year of Experian IdentityWorks credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5e90fbdf44635731Maine State AGfiled 2021-12-22Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548804
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2021
- Raw hash
- 98e12a81589acac4090402f55968b0f628f1ef68fb6b82f47e2319bd8b6095de
Reporting entity
- Name
- City of Sebastopolnorm: city of sebastopol
Victim entity
- Name
- City of Sebastopolnorm: city of sebastopol
Incident
- Discovered
- May 11, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.