HackingVulnerability ExploitCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Oklahoma Department of Securities
bd_aa9b3bc3bf25cb02 · schema v1 · pii pii-v1
Full breach record for Oklahoma Department of Securities →The Oklahoma Department of Securities discovered a vulnerability in a firewall that made a server accessible on or about November 29, 2018. The Department took immediate steps to close the vulnerability and took the server offline. An investigation confirmed that personal information, including names and addresses, may have been viewed without authorization. The incident was reported to the FBI.
California clockDiscovered Dec 11, 2018 → Notified Jun 24, 2019195d ✗ CA 60-day late27 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_f49fe78928e1c8deDelaware State AGfiled 2019-06-20Verified
- bd_f7e37dafbbc65792Hawaii State AGfiled 2019-06-25(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148278
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 20, 2019
- Raw hash
- 2f38bc2066a5b5c1c1fc2ad20b82211f6b38cce495e468bdfdc1bf232f3d2b36
Reporting entity
- Name
- Oklahoma Department of Securitiesnorm: oklahoma department of securities
Victim entity
- Name
- Oklahoma Department of Securitiesnorm: oklahoma department of securities
Incident
- Discovered
- Dec 11, 2018
- Materiality determined
- —
- Notification sent
- Jun 24, 2019
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported this incident to the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 weeks(191 days from discovery to filing)
- Compliance flags
- CA 60-day late · 195d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 11, 2018→ Notified: Jun 24, 2019195d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.