HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
CITY OF HOPE
bd_646c0dd6c4c8efee · schema v1 · pii pii-v1
Full breach record for CITY OF HOPE →City of Hope disclosed that an unauthorized third party accessed its systems and copied files between September 19 and October 12, 2023. The organization became aware of suspicious activity on October 13, 2023. Affected data may include names, contact info, SSNs, government IDs, financial details, health insurance info, and medical records. City of Hope engaged a cybersecurity firm, implemented enhanced safeguards, notified law enforcement and regulators, and offered two years of identity monitoring via Kroll.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_4e34f10272b1cbb2New Hampshire State AGfiled 2024-04-02Verified
- bd_512fd9d9da2e106bMontana State AGfiled 2024-04-02Candidate
- bd_56c727d6f5a7adc5Vermont State AGfiled 2024-04-02Verified
- bd_a206c1ef5bf16daeWashington State AGfiled 2024-04-02Verified
Show 3 more filings ↓Show fewer ↑up to 14d gap
- bd_eacec21685bd1ec2Maine State AGfiled 2024-04-02Verified
- bd_9a6d405cfd05175cOregon State AGfiled 2024-04-03(1d gap)Verified
- bd_2b407412ec00741dOregon State AGfiled 2024-04-16(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583421
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2024
- Raw hash
- ece10e9dafd7ea06f9e1ce845c97f8a75436b5bb93627cbc4529c1635fdb4d83
Reporting entity
- Name
- CITY OF HOPEnorm: city of hope
- Domain
- cityofhope.org
Victim entity
- Name
- CITY OF HOPEnorm: city of hope
- Domain
- cityofhope.org
Incident
- Discovered
- Oct 13, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified regulatory bodies
Compliance
- Time to disclose
- 25 weeks(172 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.