HackingDelayed DiscoveryPIIIDENTITY_BASICLowContained
Catholic Charities CYO of The Archdiocese of San Francisco
bd_a9586017ae4800a4 · schema v1 · pii pii-v1
Full breach record for Catholic Charities CYO of The Archdiocese of San Francisco →Catholic Charities CYO of The Archdiocese of San Francisco notified consumers of a data breach occurring between Sept 13-29, 2023, confirmed on March 20, 2024. Unauthorized access to files containing personal information (PII) occurred. The organization engaged external cybersecurity professionals and offered complimentary credit monitoring and fraud assistance via Identity Force. No specific count of affected individuals was disclosed in the filing.
Vermont clock✓ VT AG ≤14 bday9 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_594c45716ecd8d9eIndiana State AGfiled 2024-03-29Verified
- bd_8fc54adc2340aa92California State AGfiled 2024-03-29Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-03-29-catholic-charities-cyo-archdiocese-san-francisco-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 29, 2024
- Raw hash
- d0985730ce026a24eb1d61c4fec994d19dee3ddd3ab6dc189099e2ad351d488d
Reporting entity
- Name
- Catholic Charities CYO of The Archdiocese of San Francisconorm: catholic charities cyo of the archdiocese of san francisco
Victim entity
- Name
- Catholic Charities CYO of The Archdiocese of San Francisconorm: catholic charities cyo of the archdiocese of san francisco
Incident
- Discovered
- Mar 20, 2024
- Materiality determined
- Mar 29, 2024
- Notification sent
- Mar 29, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.