HackingSupply Chain (3P Vendor)Employee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENTHighContained
HUMANGOOD SOCAL
bd_9475c152d1488eb6 · schema v1 · pii pii-v1
Full breach record for HUMANGOOD SOCAL →HumanGood notified the California Attorney General that a third-party benefits coordination vendor may have accessed personal information of 4,844 HumanGood employees residing in California. The incident occurred and was discovered on September 27, 2017. Affected data included names, addresses, email addresses, dates of birth, Social Security numbers, wage information, and medical information. HumanGood notified the FBI and local law enforcement and offered 12 months of credit monitoring and identity protection services through AllClear ID.
California clockDiscovered Sep 27, 2017 → Notified Oct 17, 201720d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8da28e3733d4da79Washington State AGfiled 2017-10-30(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-103240
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2017
- Raw hash
- aef6eeec4fda1d45daaaf7e7c05a2eb6ccd1bfdb3d46b2b18e61e9e23c8e82d9
Reporting entity
- Name
- HUMANGOOD SOCALnorm: humangood socal
Victim entity
- Name
- HUMANGOOD SOCALnorm: humangood socal
Incident
- Discovered
- Sep 27, 2017
- Materiality determined
- —
- Notification sent
- Oct 17, 2017
- Affected individuals
- 4,844
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of InvestigationNotified the Pleasanton Police Department
- Third party
- via third-party benefits coordination vendor
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 20d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 27, 2017→ Notified: Oct 17, 201720d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.