MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumActive
Santa Clara Valley Transportation Authority
bd_4e052fda57651005 · schema v1 · pii pii-v1
Full breach record for Santa Clara Valley Transportation Authority →Santa Clara Valley Transportation Authority (VTA) reported a cybersecurity incident where systems were made inaccessible starting March 25, 2021, discovered on April 17, 2021. An unknown actor accessed systems, potentially exfiltrating employee data including SSNs, bank info, and medical records. VTA engaged forensic specialists and law enforcement, offering 12 months of Experian identity monitoring. The filing is a supplemental notice.
California clockDiscovered Apr 17, 2021 → Notified Aug 23, 2021128d ✗ CA 60-day late18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-544173
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2021
- Raw hash
- c18776c949ded250ee4174e178fc6c1428afcbe1c21dd21a6f1f64ca627d648e
Reporting entity
- Name
- Santa Clara Valley Transportation Authoritynorm: santa clara valley transportation authority
Victim entity
- Name
- Santa Clara Valley Transportation Authoritynorm: santa clara valley transportation authority
Incident
- Discovered
- Apr 17, 2021
- Materiality determined
- —
- Notification sent
- Aug 23, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 18 weeks(128 days from discovery to filing)
- Compliance flags
- CA 60-day late · 128d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2021→ Notified: Aug 23, 2021128d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.