HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
CORPORATION SERVICE COMPANY
bd_3f435c5b8cf60419 · schema v1 · pii pii-v1
Full breach record for CORPORATION SERVICE COMPANY →Corporation Service Company (CSC) notified the California AG of a data event affecting 5,678 residents. An unauthorized third party accessed CSC's network and exfiltrated a database table containing names, SSNs, and credit/debit card info. The intrusion was detected on April 5, 2018, though the data was accessed as early as November 25, 2017. CSC engaged forensic firms, notified law enforcement, and provided 12 months of credit monitoring.
California clockDiscovered Apr 5, 2018 → Notified May 17, 201842d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0b9793f68588a624Washington State AGfiled 2018-05-17Candidate
- bd_bc65e9cd2ef121b4Oregon State AGfiled 2018-05-17Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136307
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2018
- Raw hash
- b6f4e75206d999436c33e1ced350a92d428cf8d50c88069f2d7902ec6fe0ee33
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- CORPORATION SERVICE COMPANYnorm: corporation service
Incident
- Discovered
- Apr 5, 2018
- Materiality determined
- Apr 5, 2018
- Notification sent
- May 17, 2018
- Affected individuals
- 5,678
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 42d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 5, 2018→ Notified: May 17, 201842d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.