DisclosureLens
AccidentalGovernmentGovernmentMisconfigurationEmployee Data InvolvedIdentity (basic)Government IDMediumContained

California Department of Corrections and Rehabilitation

bd_5280a3ea5c141dd9 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 7, 2020

Filed

Jul 14, 2020

To disclose

10 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for California Department of Corrections and Rehabilitation8 incidents on file

The California Department of Corrections and Rehabilitation (CDCR) experienced a data breach involving a SharePoint site used by the Office of Peace Officer Selection. On May 6, 2020, a domain group for all CDCR staff was inadvertently granted 'read only' access to the site, which contained personal identifying information including names, Social Security numbers, and addresses. The incident was discovered on May 7, 2020. The agency immediately removed the inadvertent access and initiated an audit of SharePoint permissions. Affected individuals were notified on May 12, 2020, and advised to place fraud alerts on their credit files.

California clockDiscovered May 7, 2020Notified May 12, 20205d CA 60-day OK10 weeks discovery → filing

Incident timeline

undetected · 1 days
discovery → filing · 10 weeks / 68 days

May 6, 2020

Begins

May 7, 2020

Discovered

Jul 14, 2020

Filed

vs. sector median

1 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.