Social EngineeringEducationEducationPhishingStolen CredentialsCapture App DataEmployee Data InvolvedMulti-Stage ChainData ExfiltratedPIIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPHIMediumContained
Carmel Unified School District
bd_8e5c53cd9277ef24 · schema v1 · pii pii-v1
Full breach record for Carmel Unified School District →Carmel Unified School District experienced a phishing incident around January 5, 2019, in which an outside individual sent phishing emails to employees, resulting in unauthorized access to employee email accounts. Affected data included employee and dependent SSNs, marriage certificates, birth certificates, and medical notes. The District reset passwords, removed phishing messages, enhanced mail filtering, and offered one year of Experian IdentityWorks identity protection to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-145289
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2019
- Raw hash
- 4dad83fb9405e93e6fcf51945ab8dead40e4b10a8781347625e1fc973c1d85ee
Reporting entity
- Name
- Carmel Unified School Districtnorm: carmel unified school district
- Domain
- carmelunified.org
Victim entity
- Name
- Carmel Unified School Districtnorm: carmel unified school district
- Domain
- carmelunified.org
- Industry
- Educationllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 9, 2019
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified California Attorney General
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.