HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICCREDENTIALSLowContained
Yucaipa-Calimesa Joint USD
bd_532a020c8b5a1f13 · schema v1 · pii pii-v1
Full breach record for Yucaipa-Calimesa Joint USD →Yucaipa-Calimesa Joint Unified School District reported a data breach involving its Aeries Student/Parent Portal. In late November 2019, an unauthorized individual exploited a vulnerability in the Aeries software to access student and parent information, including names, addresses, phone numbers, emails, and hashed passwords. The District notified affected individuals in May 2020, required password changes, and installed a software patch. The perpetrator was taken into police custody.
California clockDiscovered Nov 4, 2019 → Notified May 26, 2020204d ✗ CA 60-day late30 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190581
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 2, 2020
- Raw hash
- f48d32624be6ca5b8e9bd56c1228dc5d7836181dde60b9553fdb96ab58683a72
Reporting entity
- Name
- Yucaipa-Calimesa Joint USDnorm: yucaipa calimesa joint usd
- Domain
- yucaipa-schools.community.highbond.com
- Industry
- Education
Victim entity
- Name
- Yucaipa-Calimesa Joint USDnorm: yucaipa calimesa joint usd
- Domain
- yucaipa-schools.community.highbond.com
- Industry
- Education
Incident
- Discovered
- Nov 4, 2019
- Materiality determined
- May 26, 2020
- Notification sent
- May 26, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Third party
- via Aeries
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(211 days from discovery to filing)
- Compliance flags
- CA 60-day late · 204d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 4, 2019→ Notified: May 26, 2020204d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.