HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumContained
ROSENTHAL COLLINS GROUP, L.L.C.
bd_b3edd60ba0755722 · schema v1 · pii pii-v1
Full breach record for ROSENTHAL COLLINS GROUP, L.L.C. →Rosenthal Collins Group, LLC (RCG) disclosed a cybersecurity incident on December 3, 2012, affecting customers who completed online account forms. Unauthorized access occurred on November 26-27, 2012, to a web application containing names, addresses, birth dates, Social Security numbers, income/net worth data, bank names, passwords, and email addresses. RCG shut down the application, terminated access, and engaged law enforcement and security professionals. Affected individuals were offered one year of complimentary credit monitoring through Experian.
California clockDiscovered Nov 27, 2012 → Notified Dec 3, 20126d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-37692
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 2, 2013
- Raw hash
- af031158ffe06b184b39dc333dcc7e7691f5f4a9156aa12a55bd06c6f46ee1b5
Reporting entity
- Name
- ROSENTHAL COLLINS GROUP, L.L.C.norm: rosenthal collins
- Domain
- rcgdirect.com
Victim entity
- Name
- ROSENTHAL COLLINS GROUP, L.L.C.norm: rosenthal collins
- Domain
- rcgdirect.com
Incident
- Discovered
- Nov 27, 2012
- Materiality determined
- —
- Notification sent
- Dec 3, 2012
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 27, 2012→ Notified: Dec 3, 20126d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.