DisclosureLens
AccidentalFinancial ServicesFinanceMisdeliveryCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountMediumResolved

United Services Automobile Association

bd_acfdf7cce72c481b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 30, 2024

Filed

Aug 29, 2024

To disclose

17 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for United Services Automobile Association7 incidents on file

USAA disclosed a data breach affecting California members due to a system error during a routine update to its document delivery system between April 13 and April 30, 2024. The error resulted in the inadvertent posting of some members' documents, including PII, PHI, and financial data, to other members' online accounts. USAA removed the documents, investigated the incident, and enhanced IT change management processes. Affected individuals were offered two years of Experian IdentityWorks.

California clockDiscovered Apr 30, 2024Notified Aug 27, 2024119d CA 60-day late17 weeks discovery → filing

Incident timeline

undetected · 17 days
discovery → filing · 17 weeks / 121 days

Apr 13, 2024

Begins

Apr 30, 2024

Discovered

Aug 29, 2024

Filed

vs. sector median

+9 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Maine State AGAug 28 · first
California State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.