HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICLowContained
Visit California
bd_98eddcd84ac7a1f9 · schema v1 · pii pii-v1
Full breach record for Visit California →California Cryobank LLC notified consumers of a data breach occurring between April 20-22, 2024. Unauthorized access to IT systems may have exposed names, bank account/routing numbers, payment card numbers, and health insurance information. The incident was discovered on April 21, 2024. Systems were isolated and an investigation launched. No specific affected individual count was provided in the Vermont filing, though 19 Rhode Island residents were explicitly notified.
Vermont clock✗ VT AG >45 bday47 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_36b1cb539cada28aIndiana State AGfiled 2025-03-14Verified
- bd_5d46b4ecbee67559Montana State AGfiled 2025-03-14Candidate
- bd_64dce7ff2645324aCalifornia State AGfiled 2025-03-14Verified
- bd_7981bf2586698512New Hampshire State AGfiled 2025-03-14Verified
Show 1 more filing ↓Show fewer ↑
- bd_f462a044442ea673Maryland State AGfiled 2025-03-14Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-14-california-cryobank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2025
- Raw hash
- e885e8acc4dc55a5337fe44ced995312b63a7fbf8c76589bd69758f2367baafe
Reporting entity
- Name
- Visit Californianorm: visit california
- Domain
- visitcalifornia.com
Victim entity
- Name
- Visit Californianorm: visit california
- Domain
- visitcalifornia.com
Incident
- Discovered
- Apr 21, 2024
- Materiality determined
- —
- Notification sent
- Mar 14, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Rhode Island Attorney General (19 residents notified)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 47 weeks(327 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.