HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedData PublishedCREDENTIALSIDENTITY_BASICLowContained
Sonicbids LLC
bd_9cf1bfbc9f5c3faa · schema v1 · pii pii-v1
Full breach record for Sonicbids LLC →Sonicbids LLC notified users that their usernames and passwords were publicly accessible due to unauthorized access of their third-party cloud hosting instance. The unauthorized access occurred on December 29, 2019, and was discovered on May 17, 2020. Sonicbids reset all user passwords, took the site offline, and engaged outside specialists to remediate vulnerabilities. The incident involved credentials and basic identity information (names).
California clockDiscovered May 17, 2020 → Notified May 17, 20200d ✓ CA 60-day OK4 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190975
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 16, 2020
- Raw hash
- 4da8be59e2355d9777bdf781978677ba54bc585ca4d99397b6a3d40aa5cab5fe
Reporting entity
- Name
- Sonicbids LLCnorm: sonicbids
- Domain
- sonicbids.com
Victim entity
- Name
- Sonicbids LLCnorm: sonicbids
- Domain
- sonicbids.com
Incident
- Discovered
- May 17, 2020
- Materiality determined
- —
- Notification sent
- May 17, 2020
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notifying regulatory authorities as required by lawIn contact with federal law enforcement and are cooperating as required
- Third party
- via third-party cloud hosting services
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 17, 2020→ Notified: May 17, 20200d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.