Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICHighContained
Jewish Federation Bay Area
bd_99db374c48866414 · schema v1 · pii pii-v1
Full breach record for Jewish Federation Bay Area →Jewish Community Federation reported a phishing attack targeting employee email accounts starting September 12, 2018. The breach exposed personal information, including SSNs, financial account data, and medical information, affecting 1,067 California residents. The organization secured accounts, retained forensic investigators, and provided 12 months of credit monitoring.
California clockDiscovered Oct 1, 2018 → Notified Sep 24, 2019358d ✗ CA 60-day late51 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,067 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150797
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 24, 2019
- Raw hash
- 8b30436d23943f6d5d43e6a9b455e2f211123caf9024f9529f891ec3ef1562c4
Reporting entity
- Name
- Jewish Federation Bay Areanorm: jewish federation bay area
- Domain
- jewishfed.org
Victim entity
- Name
- Jewish Federation Bay Areanorm: jewish federation bay area
- Domain
- jewishfed.org
Incident
- Discovered
- Oct 1, 2018
- Materiality determined
- Sep 24, 2019
- Notification sent
- Sep 24, 2019
- Affected individuals
- 1,067
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Reported the event to relevant state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 51 weeks(358 days from discovery to filing)
- Compliance flags
- CA 60-day late · 358d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 1, 2018→ Notified: Sep 24, 2019358d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.