Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
County of Los Angeles Department of Mental Health
bd_70c0fd0ad8b69391 · schema v1 · pii pii-v1
Full breach record for County of Los Angeles Department of Mental Health →Los Angeles County Department of Mental Health experienced a phishing incident on May 28, 2024, where employees interacted with a malicious email from a trusted partner, leading to compromised Microsoft Office 365 accounts. The breach potentially exposed names, SSNs, DOBs, addresses, phone numbers, medical record numbers, health insurance info, diagnoses, and treatment information. The organization disabled accounts, reset credentials, engaged forensic specialists, and notified law enforcement and Microsoft.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8070af4059f69d7bHHS OCRfiled 2024-09-05(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-591079
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2024
- Raw hash
- ed4287e95fb2320f14cee281b29160e4bb8f4b495f723217271412a23bfc06b2
Reporting entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Victim entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Incident
- Discovered
- May 28, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 weeks(94 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.