HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHIEMPLOYMENTEDUCATIONCriticalContained
University of California, Los Angeles
bd_80ef632ad1208b7d · schema v1 · pii pii-v1
Full breach record for University of California, Los Angeles →UCLA reported unauthorized access to its network between May 28 and June 1, 2023. An unknown third party used valid credentials to access personal information of approximately 290,000 students, employees, and patients. Data exposed included names, addresses, SSNs, financial account numbers, and health records. UCLA engaged Experian to provide credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed290,000 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-568404
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2023
- Raw hash
- 6f0acdd987f794d448c95948c1bc6c894fae49b3d50b17b767cf58937f7c3241
Reporting entity
- Name
- University of California, Los Angelesnorm: university of california los angeles
Victim entity
- Name
- University of California, Los Angelesnorm: university of california los angeles
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 290,000
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHIEMPLOYMENTEDUCATION
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the California Attorney General
- Third party
- via Experian
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.