HackingDelayed DiscoveryIDENTITY_GOVERNMENTPIIMediumContained
Catholic Charities CYO of The Archdiocese of San Francisco
bd_934e97c045cc2b3b · schema v1 · pii pii-v1
Full breach record for Catholic Charities CYO of The Archdiocese of San Francisco →Catholic Charities CYO of The Archdiocese of San Francisco notified consumers of a data breach where unauthorized access to files containing Social Security numbers occurred between September 13 and 29, 2023. The incident was confirmed via forensic investigation on July 31, 2024. The organization offered 12 months of credit monitoring and fraud assistance.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1770d100f6779aa4HHS OCRfiled 2024-08-30Verified
- bd_389ab70a0544ce2fMontana State AGfiled 2024-08-30Verified
- bd_a5398ad6ee59bc88California State AGfiled 2024-08-30Verified
- bd_b382295877ac58f8Maine State AGfiled 2024-08-30Verified by operator
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_fba3310eeb4f88d5New Hampshire State AGfiled 2024-09-06(7d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-30-catholic-charities-cyo-archdiocese-san-francisco-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2024
- Raw hash
- 7969b6bfb79408c429896be2b36e2de0f6e25c40c80cfdd3cd01a6fd4b0841e4
Reporting entity
- Name
- Catholic Charities CYO of The Archdiocese of San Francisconorm: catholic charities cyo of the archdiocese of san francisco
Victim entity
- Name
- Catholic Charities CYO of The Archdiocese of San Francisconorm: catholic charities cyo of the archdiocese of san francisco
Incident
- Discovered
- Jul 31, 2024
- Materiality determined
- Aug 30, 2024
- Notification sent
- Aug 30, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Third party
- via Cyberscout
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.