MisuseData MishandlingEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumResolved
California Department of Social Services
bd_9c7348ba71f8ae9d · schema v1 · pii pii-v1
Full breach record for California Department of Social Services →On January 6, 2023, the California Department of Social Services (CDSS) discovered that an employee emailed a document containing names, Social Security numbers, and bargaining unit numbers to their personal email account. The incident was flagged by security monitoring software. CDSS contacted the employee and required immediate deletion of the email. The Department is evaluating procedures and implementing new security controls to prevent recurrence. Affected individuals were advised to place fraud alerts on their credit files.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563292
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 16, 2023
- Raw hash
- 02f55af9cb4ff4a9be76d1f90fb779f3ecff4431162b50435803af8e5e3a4106
Reporting entity
- Name
- California Department of Social Servicesnorm: california department of social
Victim entity
- Name
- California Department of Social Servicesnorm: california department of social
Incident
- Discovered
- Jan 6, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Insider
- Threat actor
- Internal
- Regulator citations
- Reported the incident and these remediation efforts to the California Information Security Office and other agencies as required by state law
- Initial access
- insider_action
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.