DisclosureLens
Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDFinancial accountHealth (basic)HighContained

Jewish Community Federation

bd_99db374c48866414 · schema v1 · pii pii-v1

Severity

High

Discovered

Oct 1, 2018

Filed

Sep 24, 2019

To disclose

51 weeks

Affected

1,067state residents only

Linked

2 filings

Confidence

66%

Jewish Community Federation experienced a phishing attack compromising employee email accounts. Unauthorized access occurred as early as September 12, 2018, with suspicious activity first detected in October 2018. The incident exposed personal information including names, addresses, SSNs, financial account data, driver's license numbers, and medical information for 1,067 California residents. The organization secured accounts, engaged forensic investigators, and provided 12 months of credit monitoring.

California clockDiscovered Oct 1, 2018Notified Sep 24, 2019358d CA 60-day late51 weeks discovery → filing

Incident timeline

undetected · 19 days
discovery → filing · 51 weeks / 358 days

Sep 12, 2018

Begins

Oct 1, 2018

Discovered

Sep 24, 2019

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGSep 24 · first
California State AGSep 24 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.