HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
SinglePoint Outsourcing, Inc.
bd_772b7a9e530ef230 · schema v1 · pii pii-v1
Full breach record for SinglePoint Outsourcing, Inc. →SinglePoint Outsourcing, Inc. notified the California Attorney General of a data breach affecting human resource records. An unauthorized individual acquired files between November 8 and November 9, 2023. The company became aware of the incident on November 30, 2023. Affected data may include names, Social Security numbers, dates of birth, driver's license numbers, and bank account information. SinglePoint engaged forensic specialists, reset passwords, secured accounts, and implemented 24/7 monitoring. Credit monitoring was offered to affected individuals.
California clockDiscovered Nov 30, 2023 → Notified Mar 15, 2024106d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_5f14395a0e1f06bdLeak Siteplayfiled 2023-11-28(118d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_316cd5a987b7761aCalifornia State AGfiled 2024-04-12(17d gap)Verified
- bd_ac0a5785760e6fc1Vermont State AGfiled 2024-02-12(43d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583096
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2024
- Raw hash
- 629cbee754ec4a1428fc131d636b0d2676288d3c6076c823b7b8b8bd6ca1c9e5
Reporting entity
- Name
- SinglePoint Outsourcing, Inc.norm: singlepoint outsourcing
- Domain
- single-point.com
Victim entity
- Name
- SinglePoint Outsourcing, Inc.norm: singlepoint outsourcing
- Domain
- single-point.com
Incident
- Discovered
- Nov 30, 2023
- Materiality determined
- —
- Notification sent
- Mar 15, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 17 weeks(117 days from discovery to filing)
- Compliance flags
- CA 60-day late · 106dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 30, 2023→ Notified: Mar 15, 2024106d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.