CHP 11-99 Foundation
bd_abf1655a014ba033 · schema v1 · pii pii-v1
Full breach record for CHP 11-99 Foundation →CHP 11-99 Foundation experienced a data breach after a staff member clicked a malicious link in a phishing email on September 16, 2025, despite initial clearance from a third-party help desk. The attacker gained access to the staff member's email account, potentially exposing membership applications, payment forms, bank/credit card info, SSNs, and driver's license numbers. The incident was discovered on September 24, 2025, when the attacker attempted to phish the help desk. The organization has implemented MFA, changed passwords, and engaged an incident response vendor. Identity monitoring services are being provided to affected individuals.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8968a5af3b4076c4New Hampshire State AGfiled 2026-01-20(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-617575
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 23, 2026
- Raw hash
- 428e8e9e7505e613d57728fe6a358d6953b625f8200394bccff23b5f7acff813
Reporting entity
- Name
- CHP 11-99 Foundationnorm: chp 11 99
Victim entity
- Name
- CHP 11-99 Foundationnorm: chp 11 99
Incident
- Discovered
- Sep 24, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.