HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
American College of Emergency Physicians
bd_5f96d4f3a8610880 · schema v1 · pii pii-v1
Full breach record for American College of Emergency Physicians →American College of Emergency Physicians (ACEP) notified members and donors that credentials to SQL database servers were stored on a compromised server. The incident occurred between April 8, 2020, and September 21, 2020. While no evidence of unauthorized access to the SQL servers was found, names and credentials were at risk. ACEP rebuilt the server, changed passwords, and engaged Epiq to provide 12 months of credit monitoring and identity restoration services.
California clockDiscovered Sep 7, 2020 → Notified Sep 21, 202014d ✓ CA 60-day OK31 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0be2e5afe6e91c9bWashington State AGfiled 2021-04-09Candidate
- bd_1bb2a01b4668a137Montana State AGfiled 2021-04-09Verified by operator
- bd_efb6dea5be6ec97bMaine State AGfiled 2021-04-09Verified
- bd_ffe93d1094959960Oregon State AGfiled 2021-04-09Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539859
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2021
- Raw hash
- 73686c8b8aacaf87221b9283870ea1661cec86246f9c01aa9c9302a8f0639cb1
Reporting entity
- Name
- American College of Emergency Physiciansnorm: american college of emergency physicians
Victim entity
- Name
- American College of Emergency Physiciansnorm: american college of emergency physicians
Incident
- Discovered
- Sep 7, 2020
- Materiality determined
- —
- Notification sent
- Sep 21, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 31 weeks(214 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 14d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 7, 2020→ Notified: Sep 21, 202014d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.