HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICHEALTH_BASICPHILowContained
California Department of Corrections and Rehabilitation
bd_97fde22c616799e5 · schema v1 · pii pii-v1
Full breach record for California Department of Corrections and Rehabilitation →California Department of Corrections and Rehabilitation (CDCR) disclosed a data breach involving a password-protected file-sharing platform. Suspicious activity was discovered in January 2022, dating back to December 2021. An unauthorized user accessed the system, but no data was copied or downloaded. Affected data included names, addresses, contact info, and PHI (mental health, substance use treatment, COVID-19 results). CDCR shut down the platform and launched a multi-agency investigation.
California clockDiscovered Jan 1, 2022 → Notified Aug 19, 2022230d ✗ CA 60-day late33 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9563e209b3098d61HHS OCRfiled 2022-08-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556463
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2022
- Raw hash
- a80decdd0bfa420290f50be530ee31e1be4da20088642e7d17082935251f9458
Reporting entity
- Name
- California Department of Corrections and Rehabilitationnorm: california department of corrections and rehabilitation
Victim entity
- Name
- California Department of Corrections and Rehabilitationnorm: california department of corrections and rehabilitation
Incident
- Discovered
- Jan 1, 2022
- Materiality determined
- —
- Notification sent
- Aug 19, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 33 weeks(233 days from discovery to filing)
- Compliance flags
- CA 60-day late · 230d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 1, 2022→ Notified: Aug 19, 2022230d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.