HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CALIFORNIA STATE TEACHERS' RETIREMENT SYSTEM
bd_443e00c780258e1a · schema v1 · pii pii-v1
Full breach record for CALIFORNIA STATE TEACHERS' RETIREMENT SYSTEM →California State Teachers' Retirement System (CalSTRS) notified individuals of a data breach involving its third-party service provider, PBI Research Services. An unauthorized party exploited a vulnerability in PBI's secure file transfer application to access files containing CalSTRS members' names, Social Security numbers, dates of birth, and ZIP codes. CalSTRS offered affected individuals 12 months of complimentary credit monitoring through Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-568490
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2023
- Raw hash
- d748b719600b90ffdf66d2f3d9eb5bf889107705b4addf397a30e71a3b65fae9
Reporting entity
- Name
- CALIFORNIA STATE TEACHERS' RETIREMENT SYSTEMnorm: california state teachers retirement system
Victim entity
- Name
- CALIFORNIA STATE TEACHERS' RETIREMENT SYSTEMnorm: california state teachers retirement system
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via PBI Research Services
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.