HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
City of Bakersfield
bd_68989e561f8876bd · schema v1 · pii pii-v1
Full breach record for City of Bakersfield →The City of Bakersfield experienced a data breach involving its third-party payment vendor, CentralSquare Technologies. Between August 11 and October 1, 2018, unauthorized code was inserted into the Click2Gov online payment system to capture payment card data and personal information. The City removed the code, enhanced security protocols, and notified affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141746
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 12, 2018
- Raw hash
- 08e257455799c8f0d8c307e420ff19520a7c448f4d972802e2604f781ae413dc
Reporting entity
- Name
- City of Bakersfieldnorm: city of bakersfield
Victim entity
- Name
- City of Bakersfieldnorm: city of bakersfield
Incident
- Discovered
- Oct 1, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Third party
- via CentralSquare Technologies
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.