Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
California Cancer Associates for Research and Excellence – San Diego
bd_9c8ef9f985208f1e · schema v1 · pii pii-v1
Full breach record for California Cancer Associates for Research and Excellence – San Diego →California Cancer Associates for Research and Excellence - San Diego notified patients of a phishing incident where unauthorized parties accessed email and SharePoint accounts between Dec 13-16, 2024. The organization learned of the incident on June 13, 2025. Patient information including names and potentially other health data was accessed. The company is offering credit monitoring and providing additional cybersecurity training to staff.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605490
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2025
- Raw hash
- 1f24a2c66a1a6781ff5dc0ddcf602c225648e0c66d171c5918f9af278ff347f6
Reporting entity
- Name
- California Cancer Associates for Research and Excellence – San Diegonorm: california cancer associates for research and excellence san diego
Victim entity
- Name
- California Cancer Associates for Research and Excellence – San Diegonorm: california cancer associates for research and excellence san diego
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.