DisclosureLens
HackingOtherStolen CredentialsCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountMediumContained

Hello Housing

bd_4745a69a001b01ea · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 2, 2020

Filed

Jul 7, 2021

To disclose

31 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Hello Housing

Hello Housing, an affordable housing program manager in California, detected suspicious activity in its business email environment on December 2, 2020. An investigation revealed that a business email account had been compromised by an unauthorized third party between November 24 and December 3, 2020. The incident potentially exposed full names, mailing addresses, Social Security numbers, dates of birth, driver's license/state ID information, passports, medical/health insurance information, and financial account information. Hello Housing secured the email environment, engaged forensic specialists, and offered 12 months of identity monitoring through Kroll.

Incident timeline

undetected · 8 days
discovery → filing · 31 weeks / 217 days

Nov 24, 2020

Begins

Dec 2, 2020

Discovered

Jul 7, 2021

Filed

vs. sector median

+23 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.