HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Kroll Background Screening Services (Kroll)
bd_4e8cd52ff7211abb · schema v1 · pii pii-v1
Full breach record for Kroll Background Screening Services (Kroll) →Kroll Background America, Inc. reported a cyberattack targeting its computer network between June and September 2013. The incident resulted in the unauthorized acquisition of personal information, including names, dates of birth, addresses, and Social Security numbers, affecting 548 California residents. Kroll notified law enforcement, investigated the breach, and provided one year of complimentary identity theft protection services to affected individuals.
California clockDiscovered Sep 1, 2013 → Notified Nov 20, 201380d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed548 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-43342
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2013
- Raw hash
- d918eacd3b13a56889564d5b35a1df3b1e228eeedff32d917ccd8ca919bb793b
Reporting entity
- Name
- Kroll Background Screening Services (Kroll)norm: kroll background screening services kroll
Victim entity
- Name
- Kroll Background Screening Services (Kroll)norm: kroll background screening services kroll
Incident
- Discovered
- Sep 1, 2013
- Materiality determined
- Nov 20, 2013
- Notification sent
- Nov 20, 2013
- Affected individuals
- 548
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(81 days from discovery to filing)
- Compliance flags
- CA 60-day late · 80d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 1, 2013→ Notified: Nov 20, 201380d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.