HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
SITUSAMC HOLDINGS CORPORATION
bd_9fd5d288eb9921f4 · schema v1 · pii pii-v1
Full breach record for SITUSAMC HOLDINGS CORPORATION →SitusAMC Holdings Corporation notified the California AG of unauthorized access to its IT network. An external actor acquired data between Nov 13-21, 2025, after SitusAMC became aware on Nov 12, 2025. Affected data may include names, addresses, DOBs, SSNs, driver's license numbers, and financial account info. The company engaged third-party experts, notified law enforcement, and is offering 24 months of identity protection via IDX.
California clockDiscovered Nov 12, 2025 → Notified Apr 3, 2026142d ✗ CA 60-day late20 weeks discovery → filing
This filing is one of 13 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_e18d1724ef30fa6fMaine State AGfiled 2026-04-03Verified
- bd_4b06c2519a61551fTexas State AGfiled 2026-04-06(3d gap)Verified
- bd_75b585487f6fa356New Hampshire State AGfiled 2026-04-06(3d gap)Verified
- bd_0cbe44e43d4d6e6fOregon State AGfiled 2026-03-23(11d gap)Verified by operator
Show 6 more filings ↓Show fewer ↑up to 42d gap
- bd_70a785f4cf612d8cIndiana State AGfiled 2026-03-10(24d gap)Verified
- bd_8485960cdfce7d6cIndiana State AGfiled 2026-03-10(24d gap)Verified
- bd_c52f9d050e7058e1California State AGfiled 2026-03-10(24d gap)Verified
- bd_6a4691fada8d391eCalifornia State AGfiled 2026-02-20(42d gap)Verified
- bd_7916a021a8a6b3d5Washington State AGfiled 2026-02-20(42d gap)Verified
- bd_954721daf4e32cd5Oregon State AGfiled 2026-02-20(42d gap)Verified
Showing first 10 of 12 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621297
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2026
- Raw hash
- 0f67927a846b2b53ee305f7f558ba99df47857eedb0d627881874755ad75bf16
Reporting entity
- Name
- SITUSAMC HOLDINGS CORPORATIONnorm: situsamc holdings
- Domain
- situsamc.com
Victim entity
- Name
- SITUSAMC HOLDINGS CORPORATIONnorm: situsamc holdings
- Domain
- situsamc.com
Incident
- Discovered
- Nov 12, 2025
- Materiality determined
- —
- Notification sent
- Apr 3, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified certain law enforcement and governmental authorities
Compliance
- Time to disclose
- 20 weeks(142 days from discovery to filing)
- Compliance flags
- CA 60-day late · 142dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 12, 2025→ Notified: Apr 3, 2026142d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Apr 3, 2026→ AG copy submitted: Apr 3, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.