MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICLowContained
Association of California School Administrators
bd_56449ff5993e7e50 · schema v1 · pii pii-v1
Full breach record for Association of California School Administrators →Association of California School Administrators (ACSA) experienced a ransomware incident between September 23-24, 2023, where an unauthorized actor encrypted files and accessed systems. ACSA became aware of the suspicious activity on September 24, 2023. The investigation determined that names and potentially other personal information were impacted. ACSA engaged third-party cybersecurity specialists, conducted a manual review of affected files, and is offering credit monitoring and identity protection services to affected individuals. The incident has been contained.
California clockDiscovered Sep 24, 2023 → Notified May 22, 2024241d ✗ CA 60-day late34 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_05f7dcc0bd140b83Vermont State AGfiled 2024-05-22Verified
- bd_40b3f13958d53462Indiana State AGfiled 2024-05-22Verified
- bd_4d8b08bc7963ab0fNew Hampshire State AGfiled 2024-05-22Verified
- bd_724586f861f6bfc4Maine State AGfiled 2024-05-22Candidate
Show 1 more filing ↓Show fewer ↑
- bd_fc9882e474ad594bMontana State AGfiled 2024-05-22Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585791
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2024
- Raw hash
- 77739ec48b7c96cf1ae973de614dc073d02e9061b2ef62984780fb24aed35522
Reporting entity
- Name
- Association of California School Administratorsnorm: association of california school administrators
Victim entity
- Name
- Association of California School Administratorsnorm: association of california school administrators
Incident
- Discovered
- Sep 24, 2023
- Materiality determined
- —
- Notification sent
- May 22, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 34 weeks(241 days from discovery to filing)
- Compliance flags
- CA 60-day late · 241d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 24, 2023→ Notified: May 22, 2024241d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.