HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSMediumContained
Community HousingWorks
bd_4f190d732f207300 · schema v1 · pii pii-v1
Full breach record for Community HousingWorks →Community HousingWorks notified the California AG of a data breach where an unauthorized actor gained access to employee email accounts. The breach occurred between October 10 and December 22, 2023, and was discovered on December 22, 2023. Affected data includes names, SSNs, driver's license numbers, passport numbers, credit/debit card numbers, security codes/PINs, and credentials. The company engaged forensic specialists, notified law enforcement, and is offering credit monitoring.
California clockDiscovered Dec 22, 2023 → Notified Oct 7, 2024290d ✗ CA 60-day late41 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0eb93848c1eeca4dNew Hampshire State AGfiled 2024-10-07Verified
- bd_40901cad4e43acdbMontana State AGfiled 2024-10-07Candidate
- bd_7feff9d5582d0d97Indiana State AGfiled 2024-10-07Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-593013
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 7, 2024
- Raw hash
- 250744f6d58fa87b4a5bc1c92ba854aa9458814bbdb9e4e4f4779d7e1156c9f3
Reporting entity
- Name
- Community HousingWorksnorm: community housingworks
- Domain
- chworks.org
Victim entity
- Name
- Community HousingWorksnorm: community housingworks
- Domain
- chworks.org
Incident
- Discovered
- Dec 22, 2023
- Materiality determined
- —
- Notification sent
- Oct 7, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notifying applicable state and federal regulators
Compliance
- Time to disclose
- 41 weeks(290 days from discovery to filing)
- Compliance flags
- CA 60-day late · 290d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 22, 2023→ Notified: Oct 7, 2024290d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.