HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Visalia Unified School District
bd_7e11cf9fb80167e9 · schema v1 · pii pii-v1
Full breach record for Visalia Unified School District →Visalia Unified School District (California) notified affected individuals of unauthorized access to certain email accounts between January 1, 2021, and June 3, 2021. The breach exposed names and sensitive data, including government identifiers and medical information, for both staff and students/minors. VUSD offered complimentary credit monitoring via IDX and implemented enhanced security measures and employee training. No actual misuse was identified at the time of notification.
California clockDiscovered Jun 6, 2021 → Notified Dec 30, 2021207d ✗ CA 60-day late30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by ryuk about this victim predates this filing by 226 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_31700e5fe96a669dLeak Siteryukfiled 2021-05-18(226d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-549009
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 30, 2021
- Raw hash
- 32f57c01c40d555de4ced11f659d0044b6f3ae2aa613e1f26615821b6aa941bc
Reporting entity
- Name
- Visalia Unified School Districtnorm: visalia unified school district
- Domain
- vusd.org
Victim entity
- Name
- Visalia Unified School Districtnorm: visalia unified school district
- Domain
- vusd.org
Incident
- Discovered
- Jun 6, 2021
- Materiality determined
- —
- Notification sent
- Dec 30, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(207 days from discovery to filing)
- Compliance flags
- CA 60-day late · 207dLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2021→ Notified: Dec 30, 2021207d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.