Storagefront
bd_6aa6a9cecb9e8d68 · schema v1 · pii pii-v1
Full breach record for Storagefront →Storagefront.com notified the California AG of a cybersecurity incident originating in 2020 where a database table was copied. The company was alerted on November 15, 2022, that data from this table appeared on the dark web. Investigation confirmed the leak but found no sensitive PII in that specific table. However, on January 5, 2023, the company discovered that other tables in the same database contained names, driver's license numbers, and Social Security numbers. While there is no evidence these specific tables were accessed, customers are being offered 12 months of credit monitoring.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563745
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 1, 2023
- Raw hash
- c9b9ad64eb45f5ca50b649f91abd5523b5fe864bbea30ec258477b2c2a2547ed
Reporting entity
- Name
- Midtown Tenant LLCnorm: midtown tenant
- Domain
- storagefront.com
Victim entity
- Name
- Storagefrontnorm: storagefront
- Domain
- storagefront.com
Incident
- Discovered
- Nov 15, 2022
- Materiality determined
- —
- Notification sent
- Feb 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- CA 60-day late · 105d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 15, 2022→ Notified: Feb 28, 2023105d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.