DisclosureLens
HackingEnergy & UtilitiesUtilitiesVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Cucamonga Valley Water District (cvwdwater.com)

bd_927ac56cebf81df9 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 6, 2019

Filed

Dec 4, 2019

To disclose

28 days

Affected

Not disclosed

Confidence

66%
Full breach record for Cucamonga Valley Water District (cvwdwater.com)2 incidents on file

Cucamonga Valley Water District notified customers that its payment vendor, Click2Gov, was targeted by a cyberattack involving an unauthorized script in its web payment portal. The incident affected customers who paid bills online between August 26, 2019, and October 14, 2019. Exposed data included names, billing addresses, and credit card details. The vendor removed the script, launched a forensic investigation, and contacted the FBI. Credit monitoring was offered to affected individuals.

Incident timeline

undetected · 72 days
discovery → filing · 28 days

Aug 26, 2019

Begins

Nov 6, 2019

Discovered

Dec 4, 2019

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.