Social EngineeringPhishingStolen CredentialsCapture App DataMulti-Stage ChainCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPIIPCIFINANCIALIDENTITY_GOVERNMENTMediumActive
CHP 11-99 Foundation
bd_6a3a425bd0f43a40 · schema v1 · pii pii-v1
Full breach record for CHP 11-99 Foundation →On or about September 16, 2025, a CHP 11-99 Foundation staff member clicked a phishing link after an external service provider's Help Desk incorrectly cleared it as safe. The attacker gained full access to the staff member's email account, including membership applications and payment documents containing bank/credit card information, driver's license numbers, Social Security numbers, names, addresses, and email addresses. Discovery occurred on September 24, 2025, when the attacker attempted to use the compromised account to phish the Help Desk.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621146
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 16, 2025
- Raw hash
- 284969ef8a19f7a8012a5b572d86be667e7dde1cdbc73a81c7164ce219efc59b
Reporting entity
- Name
- CHP 11-99 Foundationnorm: chp 11 99
Victim entity
- Name
- CHP 11-99 Foundationnorm: chp 11 99
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPCIFINANCIALIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified California Office of the Attorney General per SB 24 data breach reporting requirements
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.