HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICCREDENTIALSLowContained
Red Bluff High School
bd_906c381b031c617b · schema v1 · pii pii-v1
Full breach record for Red Bluff High School →Red Bluff Joint Union High School District (California) notified parents and students of a data breach involving the Aeries Student Information System. An unauthorized individual exploited a vulnerability in the Aeries software in late November 2019, accessing parent and student data including names, addresses, phone numbers, emails, and hashed passwords. The District discovered the breach in May 2020, patched the vulnerability, and is reviewing security policies. Law enforcement investigated and believes the suspect is in custody.
California clockDiscovered May 6, 2020 → Notified May 6, 20200d ✓ CA 60-day OK8 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-191519
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2020
- Raw hash
- bf9fc5d98fb65a7cf9b983d637b8fe34729ea42a4c1f1bddac916d3f2bc7d220
Reporting entity
- Name
- Red Bluff High Schoolnorm: red bluff high school
- Domain
- rbhs.rbhsd.org
- Industry
- Education
Victim entity
- Name
- Red Bluff High Schoolnorm: red bluff high school
- Domain
- rbhs.rbhsd.org
- Industry
- Education
Incident
- Discovered
- May 6, 2020
- Materiality determined
- May 6, 2020
- Notification sent
- May 6, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Law enforcement launched an investigation to identify the person responsible
- Third party
- via Aeries
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 6, 2020→ Notified: May 6, 20200d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.