HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumResolved
Visit California
bd_64dce7ff2645324a · schema v1 · pii pii-v1
Full breach record for Visit California →California Cryobank LLC notified the California Attorney General of a data breach where an unauthorized party accessed its IT environment between April 20-22, 2024. The incident was discovered on April 21, 2024. Affected data includes names, Social Security numbers, driver's license numbers, financial account numbers, and health insurance information. The company isolated affected systems, conducted an investigation, and is offering 12 months of identity protection services to affected individuals.
California clockDiscovered Apr 21, 2024 → Notified Mar 14, 2025327d ✗ CA 60-day late47 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_36b1cb539cada28aIndiana State AGfiled 2025-03-14Verified
- bd_5d46b4ecbee67559Montana State AGfiled 2025-03-14Candidate
- bd_7981bf2586698512New Hampshire State AGfiled 2025-03-14Verified
- bd_98eddcd84ac7a1f9Vermont State AGfiled 2025-03-14Verified
Show 1 more filing ↓Show fewer ↑
- bd_f462a044442ea673Maryland State AGfiled 2025-03-14Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-599946
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2025
- Raw hash
- bfbea2123d7522981dc788455b6f934b055ddd331f895f0816381ebd1437c155
Reporting entity
- Name
- Visit Californianorm: visit california
- Domain
- visitcalifornia.com
Victim entity
- Name
- Visit Californianorm: visit california
- Domain
- visitcalifornia.com
Incident
- Discovered
- Apr 21, 2024
- Materiality determined
- —
- Notification sent
- Mar 14, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 47 weeks(327 days from discovery to filing)
- Compliance flags
- CA 60-day late · 327d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 21, 2024→ Notified: Mar 14, 2025327d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.