HackingCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICEMPLOYMENTLowContained
Complete Payroll Solutions
bd_a438c7e68790c182 · schema v1 · pii pii-v1
Full breach record for Complete Payroll Solutions →Complete Payroll Solutions (CPS) notified the California Attorney General of a data breach affecting client employee data. Unauthorized access occurred between February 21, 2024, and March 10, 2024. CPS identified suspicious activity on March 10, 2024. An unknown external actor accessed information including names and other personal data. CPS reset passwords, added security layers, notified law enforcement, and offered identity monitoring via Kroll.
Leak gap clock✗ Leak >180d14 months discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_62a43e32f3202618Leak Sitemeowfiled 2024-08-26(241d gap)Candidate
Regulatory filings (3) · sorted by filing gap
- bd_8098ebc1bce71e1cMontana State AGfiled 2025-04-25Verified by operator
- bd_956ff6e14c25a6deCalifornia State AGfiled 2025-05-09(14d gap)Verified
- bd_33129bc371be906dMaine State AGfiled 2024-10-23(184d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601920
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2025
- Raw hash
- a73910f061a6acd7a7a59a86a1c15595abc3de1e20153f303e30faa32519c101
Reporting entity
- Name
- Complete Payroll Solutionsnorm: complete payroll
- Domain
- completepayrollsolutions.com
Victim entity
- Name
- Complete Payroll Solutionsnorm: complete payroll
- Domain
- completepayrollsolutions.com
Incident
- Discovered
- Mar 10, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 14 months(411 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.