City of Oceanside
bd_5ce119809af5785c · schema v1 · pii pii-v1
The City of Oceanside experienced a cyberattack on its online utility bill payment system between June 1 and August 15, 2017. Malicious code infiltrated the vendor-supported system, exposing names, billing addresses, and credit card information (including security codes) of customers who paid bills online. The City discovered the breach on August 14, 2017, after a consumer notification. The affected system was shut down, and law enforcement and forensic experts were engaged.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 1, 2017
Begins
Aug 14, 2017
Discovered
Sep 6, 2017
Filed
vs. sector median
8 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.