HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIALEMPLOYMENTMediumContained
Laboratory Services Cooperative
bd_3b53713c4b166ab5 · schema v1 · pii pii-v1
Full breach record for Laboratory Services Cooperative →Laboratory Services Cooperative (LSC) notified individuals of a security incident detected on October 27, 2024, where an unauthorized third party accessed and removed files from LSC's network. The breach potentially affected patient and worker data, including PHI (diagnoses, lab results), PII (SSN, driver's license), and financial information (bank accounts, payment cards). LSC engaged forensic specialists, notified law enforcement, and is offering credit and medical identity monitoring. No specific malware or ransomware was identified.
California clockDiscovered Oct 27, 2024 → Notified Apr 10, 2025165d ✗ CA 60-day late23 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_102212ae480e10daVermont State AGfiled 2025-04-10(1d gap)Verified
- bd_18cb69ce78d99e82Washington State AGfiled 2025-04-10(1d gap)Candidate
- bd_721c52ac63a845caOregon State AGfiled 2025-04-10(1d gap)Verified
- bd_891e39ad753077a2Indiana State AGfiled 2025-04-10(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_b2eb717e40560ef3Maine State AGfiled 2025-04-10(1d gap)Verified
- bd_c3c9c68a034fcdd4Iowa State AGfiled 2025-04-10(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601185
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2025
- Raw hash
- 284087ba58747505532739f1938140175184c6fb04a75eac13a4381d37d76982
Reporting entity
- Name
- Laboratory Services Cooperativenorm: laboratory services cooperative
Victim entity
- Name
- Laboratory Services Cooperativenorm: laboratory services cooperative
Incident
- Discovered
- Oct 27, 2024
- Materiality determined
- —
- Notification sent
- Apr 10, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIALEMPLOYMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 23 weeks(164 days from discovery to filing)
- Compliance flags
- CA 60-day late · 165d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 27, 2024→ Notified: Apr 10, 2025165d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.