DisclosureLens
Social EngineeringOtherPhishingStolen CredentialsCapture App DataMulti-Stage ChainCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPIIPCIFinancialGovernment IDMediumActive

CHP 11-99 Foundation

bd_6a3a425bd0f43a40 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Apr 1, 2026

To disclose

Affected

Not disclosed

Confidence

84%
Full breach record for CHP 11-99 Foundation2 incidents on file

On or about September 16, 2025, a CHP 11-99 Foundation staff member clicked a phishing link after an external service provider's Help Desk incorrectly cleared it as safe. The attacker gained full access to the staff member's email account, including membership applications and payment documents containing bank/credit card information, driver's license numbers, Social Security numbers, names, addresses, and email addresses. Discovery occurred on September 24, 2025, when the attacker attempted to use the compromised account to phish the Help Desk.

Incident timeline

Sep 16, 2025

Begins

Apr 1, 2026

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.