HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPHILowContained
Schewitz Psychological Services Inc
bd_61c2911985257f3b · schema v1 · pii pii-v1
Full breach record for Schewitz Psychological Services Inc →Schewitz Psychological Services Inc (DBA: Couples Learn) reported that an unauthorized individual accessed their Acuity Scheduling account via a hacked staff password on or around March 10, 2025. The actor uploaded external email addresses and sent spam emails. Limited scheduling information (name, email, phone, appointment type) may have been accessed. No clinical records were involved. The incident has been contained.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-602225
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2025
- Raw hash
- e860d80b2a7fbe6d9173298f9567aa6542f6f247040479180f1ec957498be62f
Reporting entity
- Name
- Schewitz Psychological Services Incnorm: schewitz psychological
- Domain
- coupleslearn.com
Victim entity
- Name
- Schewitz Psychological Services Incnorm: schewitz psychological
- Domain
- coupleslearn.com
Incident
- Discovered
- Mar 10, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Acuity Scheduling
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.