HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICPIILowContained
PUC National
bd_b3c1ed6ad8c11ffa · schema v1 · pii pii-v1
Full breach record for PUC National →PUC National notified the California Attorney General of a data breach discovered on January 26, 2021. An unauthorized actor downloaded information from PUC email accounts. Affected data includes names and other personal information. PUC engaged forensic investigators, secured accounts, and offered 12 months of identity protection via Equifax.
California clockDiscovered Jan 26, 2021 → Notified Sep 10, 2021227d ✗ CA 60-day late42 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547680
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2021
- Raw hash
- 4b29066200a6c500e5be9a9f32f5413f6374a649494cf5a4c1d1dbf53b8d9fc5
Reporting entity
- Name
- PUC Nationalnorm: puc national
Victim entity
- Name
- PUC Nationalnorm: puc national
Incident
- Discovered
- Jan 26, 2021
- Materiality determined
- —
- Notification sent
- Sep 10, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 42 weeks(295 days from discovery to filing)
- Compliance flags
- CA 60-day late · 227d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 26, 2021→ Notified: Sep 10, 2021227d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.