DisclosureLens
HackingGovernmentGovernmentData ExfiltratedData Leak ThreatenedEmployee Data InvolvedGovernment IDIdentity (basic)Financial accountHealth (basic)CredentialsMediumActive

California Department of Finance

bd_48972b6f910c8603 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 9, 2022

Filed

Dec 30, 2022

To disclose

21 days

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for California Department of Finance

The California Department of Finance experienced a cybersecurity incident on December 6, 2022, where data was unlawfully obtained from its servers. The intrusion was identified proactively through coordination with security partners. The incident potentially affected personnel data for a small number of former employees, including names, SSNs, employee IDs, home addresses, phone numbers, bank account information, and medical information. There was a threat to release the obtained data. The department engaged threat-hunting experts and is providing credit monitoring services.

California clockDiscovered Dec 9, 2022Notified Dec 16, 20227d CA 60-day OK21 days discovery → filing

Incident timeline

undetected · 3 days
discovery → filing · 21 days

Dec 6, 2022

Begins

Dec 9, 2022

Discovered

Dec 30, 2022

Filed

vs. sector median

8 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.