HackingStolen CredentialsTargetedIDENTITY_BASICPIILowContained
Housing Authority of the County of San Bernardino
bd_405152691464335a · schema v1 · pii pii-v1
Full breach record for Housing Authority of the County of San Bernardino →Housing Authority of the County of San Bernardino notified consumers of unauthorized access to an employee email account discovered on June 19, 2023. The incident potentially exposed names combined with other data elements. No evidence of fraudulent misuse was found. The Authority engaged forensic investigators, reset passwords, and offered complimentary credit monitoring via IDX.
Vermont clock✗ VT AG >45 bday28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_a061da6246ee57fbIndiana State AGfiled 2024-01-02Verified
- bd_3d50aebe2c4e8019New Hampshire State AGfiled 2024-01-03(1d gap)Verified
- bd_7287adc2de377fe0Montana State AGfiled 2024-01-03(1d gap)Candidate
- bd_de2d36b21007fc2aCalifornia State AGfiled 2024-01-03(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_c794c4e88c630312Maine State AGfiled 2024-01-04(2d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-02-housing-authority-county-san-bernardino-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 2, 2024
- Raw hash
- 8c794d6b95624a7b3282f568913c59f84e6a4a89529b65067679c009f60b1f0a
Reporting entity
- Name
- Housing Authority of the County of San Bernardinonorm: housing authority of the county of san bernardino
Victim entity
- Name
- Housing Authority of the County of San Bernardinonorm: housing authority of the county of san bernardino
Incident
- Discovered
- Jun 19, 2023
- Materiality determined
- —
- Notification sent
- Jan 2, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 weeks(197 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.