California Department of Corrections and Rehabilitation
bd_5280a3ea5c141dd9 · schema v1 · pii pii-v1
Full breach record for California Department of Corrections and Rehabilitation →8 incidents on fileThe California Department of Corrections and Rehabilitation (CDCR) experienced a data breach involving a SharePoint site used by the Office of Peace Officer Selection. On May 6, 2020, a domain group for all CDCR staff was inadvertently granted 'read only' access to the site, which contained personal identifying information including names, Social Security numbers, and addresses. The incident was discovered on May 7, 2020. The agency immediately removed the inadvertent access and initiated an audit of SharePoint permissions. Affected individuals were notified on May 12, 2020, and advised to place fraud alerts on their credit files.
J jump to incidentP pin to compareR raw source
Incident timeline
May 6, 2020
Begins
May 7, 2020
Discovered
Jul 14, 2020
Filed
vs. sector median
1 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.