MalwareRansomwareData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICPIILowContained
Hacienda La Puente Unified School District
bd_40af77a4100bceab · schema v1 · pii pii-v1
Full breach record for Hacienda La Puente Unified School District →Hacienda La Puente Unified School District experienced a ransomware attack. Unauthorized access occurred from February 9, 2024, to April 12, 2024. The incident was discovered on April 12, 2024. The district engaged third-party forensic specialists, secured the network, and reported the incident to federal law enforcement and the California Cybersecurity Integration Center. Affected individuals may have had their names and other personal information exposed. The district is offering complimentary credit monitoring services.
California clockDiscovered Apr 12, 2024 → Notified Aug 15, 2025490d ✗ CA 60-day late17 months discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1d319057400a676aNew Hampshire State AGfiled 2025-09-02(15d gap)Verified
- bd_dc6c623cdafb506cVermont State AGfiled 2025-08-29(19d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-610217
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 17, 2025
- Raw hash
- 4202b67c66f28eb551f159a12b344f79bf73f41dd86e004f983acfb10713c5d3
Reporting entity
- Name
- Hacienda La Puente Unified School Districtnorm: hacienda la puente unified school district
- Domain
- hlpschools.org
Victim entity
- Name
- Hacienda La Puente Unified School Districtnorm: hacienda la puente unified school district
- Domain
- hlpschools.org
Incident
- Discovered
- Apr 12, 2024
- Materiality determined
- —
- Notification sent
- Aug 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to federal law enforcement and the California Cybersecurity Integration Center
Compliance
- Time to disclose
- 17 months(523 days from discovery to filing)
- Compliance flags
- CA 60-day late · 490d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 12, 2024→ Notified: Aug 15, 2025490d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.