HackingStolen CredentialsDelayed DiscoveryCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALSMediumContained
Seneca Family of Agencies
bd_494d19c84e30b77e · schema v1 · pii pii-v1
Full breach record for Seneca Family of Agencies →Seneca Family of Agencies disclosed a data incident where an unauthorized individual accessed its network between August 25-27, 2021. The breach potentially exposed names, SSNs, DOBs, medical records, and financial data. Seneca reported to law enforcement, reset passwords, and offered credit monitoring. No evidence of misuse was found.
California clockDiscovered Aug 27, 2021 → Notified Oct 23, 202157d ✓ CA 60-day OK14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e67dfe48ecde7b1fCalifornia State AGfiled 2021-12-10(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548287
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2021
- Raw hash
- 41bf27f23a12b7e40fc43a5b825d1959152199d7c764616526fb87521ce131da
Reporting entity
- Name
- Seneca Family of Agenciesnorm: seneca family of agencies
- Domain
- senecafoa.org
Victim entity
- Name
- Seneca Family of Agenciesnorm: seneca family of agencies
- Domain
- senecafoa.org
Incident
- Discovered
- Aug 27, 2021
- Materiality determined
- —
- Notification sent
- Oct 23, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(101 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 57d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 27, 2021→ Notified: Oct 23, 202157d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.