MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICLowContained
Merced College
bd_696a93ae91c3c622 · schema v1 · pii pii-v1
Full breach record for Merced College →Merced College experienced a cybersecurity incident involving malware that encrypted systems between October 25 and November 3, 2022. An unauthorized party may have accessed personal information including names and addresses. The college secured its network, launched an investigation, and offered 12 months of identity monitoring through IDX to affected individuals.
California clockDiscovered Nov 3, 2022 → Notified Mar 9, 2023126d ✗ CA 60-day late18 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564094
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2023
- Raw hash
- 287c2dcfaf102d604f06a3b0e144061817d6e66f6bfc13eb9d1bbc7487908141
Reporting entity
- Name
- Merced Collegenorm: merced college
Victim entity
- Name
- Merced Collegenorm: merced college
Incident
- Discovered
- Nov 3, 2022
- Materiality determined
- —
- Notification sent
- Mar 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
Compliance
- Time to disclose
- 18 weeks(125 days from discovery to filing)
- Compliance flags
- CA 60-day late · 126d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 3, 2022→ Notified: Mar 9, 2023126d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.