DisclosureLens
MalwareEducationProfessional ServicesEducationRansomwareData EncryptedCustomer Data InvolvedIdentity (basic)LowContained

Association of California School Administrators

bd_56449ff5993e7e50 · schema v1 · pii pii-v1

Severity

Low

Discovered

Sep 24, 2023

Filed

May 22, 2024

To disclose

34 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

65%
Full breach record for Association of California School Administrators

Association of California School Administrators (ACSA) experienced a ransomware incident between September 23-24, 2023, where an unauthorized actor encrypted files and accessed systems. ACSA became aware of the suspicious activity on September 24, 2023. The investigation determined that names and potentially other personal information were impacted. ACSA engaged third-party cybersecurity specialists, conducted a manual review of affected files, and is offering credit monitoring and identity protection services to affected individuals. The incident has been contained.

California clockDiscovered Sep 24, 2023Notified May 22, 2024241d CA 60-day late34 weeks discovery → filing

Incident timeline

undetected · 1 days
discovery → filing · 34 weeks / 241 days

Sep 23, 2023

Begins

Sep 24, 2023

Discovered

May 22, 2024

Filed

vs. sector median

+24 wks slower

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filings

Filing propagation · 7 filings · 7 states

View merged incident ↗
Vermont State AGMay 22 · first
Indiana State AGMay 22 · first
New Hampshire State AGMay 22 · first
Massachusetts State AGMay 22 · first
Maine State AGMay 22 · first
Montana State AGMay 22 · first
California State AGMay 22 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.