HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICLowContained
STUDENT TRANSPORTATION OF AMERICA, INC.
bd_3ad69f7896265a11 · schema v1 · pii pii-v1
Full breach record for STUDENT TRANSPORTATION OF AMERICA, INC. →Student Transportation of America (STA) notified the California AG of a security incident where an unauthorized actor gained access to employee email accounts. The breach window is Jan 17-24, 2024, with discovery on Jan 24, 2024. STA engaged forensic specialists, secured the email tenant, and notified law enforcement. Affected individuals may have had PII exposed. STA is offering 12 months of credit monitoring and fraud assistance. Rhode Island residents are also noted as potentially impacted.
California clockDiscovered Jan 24, 2024 → Notified Aug 8, 2024197d ✗ CA 60-day late28 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0fa8b4c088a6959bMontana State AGfiled 2024-08-08Candidate
- bd_120ff8acd6aaf495Vermont State AGfiled 2024-08-08Verified
- bd_19e309ad87559e21New Hampshire State AGfiled 2024-08-08Verified
- bd_1d705831f299146fIndiana State AGfiled 2024-08-08Verified
Show 1 more filing ↓Show fewer ↑
- bd_e8e795c06a880890Maine State AGfiled 2024-08-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-589996
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 8, 2024
- Raw hash
- 9c1bc4cef7976dd90bb9275b925a03460982d99a8f8bd57a2dcc2e3beac7699f
Reporting entity
- Name
- STUDENT TRANSPORTATION OF AMERICA, INC.norm: student transportation of america
- Domain
- ridesta.com
Victim entity
- Name
- STUDENT TRANSPORTATION OF AMERICA, INC.norm: student transportation of america
- Domain
- ridesta.com
Incident
- Discovered
- Jan 24, 2024
- Materiality determined
- —
- Notification sent
- Aug 8, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 weeks(197 days from discovery to filing)
- Compliance flags
- CA 60-day late · 197d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 24, 2024→ Notified: Aug 8, 2024197d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.