PhysicalTheftCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Santa Cruz Biotechnology, Inc.
bd_49e04d671ab27e50 · schema v1 · pii pii-v1
Full breach record for Santa Cruz Biotechnology, Inc. →Santa Cruz Biotechnology, Inc. reported a physical burglary at its Santa Cruz office on December 17, 2017, resulting in the theft of two HR computers. The incident involved the potential unauthorized access to employee and beneficiary personal information, including names, addresses, SSNs, and medical/health insurance data. The company engaged law enforcement and the FBI, implemented encryption and remote-destroy software, and offered one year of identity protection services to affected individuals.
California clockDiscovered Dec 18, 2017 → Notified Mar 30, 2018102d ✗ CA 60-day late15 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1230217910e533d7California State AGfiled 2018-02-22(36d gap)Verified
- bd_b1ae7a75e8e1e802Montana State AGfiled 2018-02-22(36d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134930
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2018
- Raw hash
- 102c7b5dc6216442f0fe38c222dfbee1dba16adf0d32f97fac892949914b7c3c
Reporting entity
- Name
- Santa Cruz Biotechnology, Inc.norm: santa cruz biotechnology
Victim entity
- Name
- Santa Cruz Biotechnology, Inc.norm: santa cruz biotechnology
Incident
- Discovered
- Dec 18, 2017
- Materiality determined
- —
- Notification sent
- Mar 30, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- CA 60-day late · 102d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 18, 2017→ Notified: Mar 30, 2018102d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.