DisclosureLens
HackingTransportation & LogisticsTransportationData ExfiltratedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountHealth (basic)PHIMediumActive

Santa Clara Valley Transportation Authority

bd_4e052fda57651005 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 17, 2021

Filed

Aug 23, 2021

To disclose

18 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Santa Clara Valley Transportation Authority2 incidents on file

Santa Clara Valley Transportation Authority (VTA) notified employees of a data breach where an unknown actor accessed systems between March 25 and April 17, 2021. VTA discovered inaccessible systems on April 17, 2021. Employee data including names, addresses, SSNs, bank account info, and medical/health insurance information may have been exfiltrated. VTA engaged forensic specialists and law enforcement, and offered 12 months of identity monitoring via Experian. The investigation is ongoing.

Incident timeline

undetected · 23 days
discovery → filing · 18 weeks / 128 days

Mar 25, 2021

Begins

Apr 17, 2021

Discovered

Aug 23, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.