MisuseData MishandlingEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
Dover Federal Credit Union
bd_3a8f52360bced411 · schema v1 · pii pii-v1
Full breach record for Dover Federal Credit Union →Dover Federal Credit Union notified members that an employee transferred files containing personal information (name, address, account number, SSN) to a personal Dropbox account for business purposes. The incident was discovered on September 20, 2016. Investigation concluded it was unlikely unauthorized persons accessed the data. The credit union updated security controls and offered identity protection services.
California clockDiscovered Sep 20, 2016 → Notified Dec 22, 201693d ✗ CA 60-day late13 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_79f7454d87adffd8Montana State AGfiled 2016-12-22Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65580
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2016
- Raw hash
- 313a036f6ee3cb48991cea53076445dba94516ba075e4c541ed9a478fa545e00
Reporting entity
- Name
- Dover Federal Credit Unionnorm: dover federal credit union
Victim entity
- Name
- Dover Federal Credit Unionnorm: dover federal credit union
Incident
- Discovered
- Sep 20, 2016
- Materiality determined
- —
- Notification sent
- Dec 22, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Insider
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- CA 60-day late · 93d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 20, 2016→ Notified: Dec 22, 201693d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.