DisclosureLens
HackingTechnologyInformationData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDMediumContained

Storagefront

bd_6aa6a9cecb9e8d68 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 15, 2022

Filed

Mar 1, 2023

To disclose

15 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for Storagefront

Storagefront.com notified the California AG of a cybersecurity incident originating in 2020 where a database table was copied. The company was alerted on November 15, 2022, that data from this table appeared on the dark web. Investigation confirmed the leak but found no sensitive PII in that specific table. However, on January 5, 2023, the company discovered that other tables in the same database contained names, driver's license numbers, and Social Security numbers. While there is no evidence these specific tables were accessed, customers are being offered 12 months of credit monitoring.

California clockDiscovered Nov 15, 2022Notified Feb 28, 2023105d CA 60-day late15 weeks discovery → filing

Incident timeline

undetected · 1049 days
discovery → filing · 15 weeks / 106 days

Jan 1, 2020

Begins

Nov 15, 2022

Discovered

Mar 1, 2023

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.