HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICEMPLOYMENTLowContained
LCPtracker
bd_4ac47077bd9ff2d3 · schema v1 · pii pii-v1
Full breach record for LCPtracker →LCPtracker, Inc. experienced unauthorized access to its online storage account environment between August 14 and August 20, 2024. The company became aware of the incident on August 20, 2024. An unauthorized actor accessed and acquired certain files and data. The company engaged a third-party cybersecurity firm for investigation and is providing 12 months of credit monitoring and fraud assistance to affected individuals. The incident involved sensitive personal information related to payroll and workforce reporting services.
California clockDiscovered Aug 20, 2024 → Notified Jan 10, 2025143d ✗ CA 60-day late21 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_5fe6cef2935f0f9cCalifornia State AGfiled 2024-12-20(25d gap)Candidate
- bd_0e244ae40a6462c9New Hampshire State AGfiled 2024-11-22(53d gap)Verified
- bd_34557b06fe467f71Washington State AGfiled 2024-11-22(53d gap)Candidate
- bd_4726fd00272b61e6Montana State AGfiled 2024-11-22(53d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 53d gap
- bd_520a0c887a11a295Vermont State AGfiled 2024-11-22(53d gap)Verified
- bd_8fd5b2be60792c2fMaine State AGfiled 2024-11-22(53d gap)Verified
- bd_f0bef15520af331eIndiana State AGfiled 2024-11-22(53d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-597348
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2025
- Raw hash
- ce377235c27df3fba7c74f4468563ece18acb30e531f98e06559a44c6bcce6ce
Reporting entity
- Name
- LCPtrackernorm: lcptracker
- Domain
- prod-cdn.lcptracker.net
Victim entity
- Name
- LCPtrackernorm: lcptracker
- Domain
- prod-cdn.lcptracker.net
Incident
- Discovered
- Aug 20, 2024
- Materiality determined
- —
- Notification sent
- Jan 10, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 21 weeks(147 days from discovery to filing)
- Compliance flags
- CA 60-day late · 143d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 20, 2024→ Notified: Jan 10, 2025143d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.