DisclosureLens
HackingProfessional ServicesProfessional ServicesCustomer Data InvolvedIdentity (basic)Government IDMediumContained

RKA Consulting Group

bd_93a0dacd8d6680e2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 8, 2025

Filed

Oct 27, 2025

To disclose

42 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for RKA Consulting Group

RKA Consulting Group notified the California Attorney General of a data security incident. On January 8, 2025, the company discovered suspicious activity and disconnected affected systems. An investigation determined that an unauthorized individual gained access to systems for a limited period. The incident potentially impacted names, dates of birth, and Social Security numbers of individuals who worked with RKA Consulting on engineering projects. The company engaged forensic experts, changed passwords, implemented network access restrictions, and is providing 12 months of credit monitoring and fraud assistance services via Cyberscout.

California clockDiscovered Jan 8, 2025Notified Oct 27, 2025292d CA 60-day late42 weeks discovery → filing

Incident timeline

discovery → filing · 42 weeks / 292 days

Jan 8, 2025

Discovered

Oct 27, 2025

Filed

vs. sector median

+24 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.