Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICCREDENTIALSMediumActive
Roadrunner Transportation Services
bd_6ffaaff7a487387b · schema v1 · pii pii-v1
Full breach record for Roadrunner Transportation Services →Roadrunner Transportation Systems, Inc. filed a supplemental California data breach notice regarding a phishing campaign. Employees clicked malicious emails in April 2018, leading to unauthorized access to email accounts containing customer PII, financial data, and health information. 937 California residents were notified in September 2018, with 463 additional residents notified in October 2018. Credit monitoring was provided.
California clockDiscovered Jul 2, 2018 → Notified Sep 10, 201870d ✗ CA 60-day late14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed937 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-140607
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2018
- Raw hash
- 187005cdacb51cc851b5305a652e359b80e5f2eb89b8c91e5e10030c915ad868
Reporting entity
- Name
- Roadrunner Transportation Servicesnorm: roadrunner transportation
Victim entity
- Name
- Roadrunner Transportation Servicesnorm: roadrunner transportation
Incident
- Discovered
- Jul 2, 2018
- Materiality determined
- Sep 10, 2018
- Notification sent
- Sep 10, 2018
- Affected individuals
- 937
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted supplemental notice to California Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 weeks(99 days from discovery to filing)
- Compliance flags
- CA 60-day late · 70d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 2, 2018→ Notified: Sep 10, 201870d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.