HackingData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Children's Council of San Francisco
bd_ac66c0f72cc2eaf3 · schema v1 · pii pii-v1
Full breach record for Children's Council of San Francisco →Children's Council of San Francisco disclosed a data breach occurring on August 3, 2025, where an unknown actor accessed personal information including names and Social Security Numbers. The organization engaged forensic experts, notified the FBI, and offered 12 months of credit monitoring and identity theft protection via TransUnion/Cyberscout. Notification was sent in February 2026.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_13cc3591bebd9bb2Maine State AGfiled 2026-03-03Verified by operator
- bd_d544b6922b9ab320New Hampshire State AGfiled 2026-03-03Verified
- bd_f70372d1a991c750California State AGfiled 2026-02-27(4d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-03-childrens-council-san-francisco-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 3, 2026
- Raw hash
- 55f56530f19b5888ee212594f06e95aac3e4fb795e7afdecf8f9701aa8abd7e6
Reporting entity
- Name
- Children's Council of San Francisconorm: children s council of san francisco
Victim entity
- Name
- Children's Council of San Francisconorm: children s council of san francisco
Incident
- Discovered
- Aug 3, 2025
- Materiality determined
- —
- Notification sent
- Feb 27, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.