HackingVulnerability ExploitTamperingData ExfiltratedCustomer Data InvolvedCREDENTIALSIDENTITY_BASICLowContained
Institute for Public Architecture
bd_b9e8d9c84fb93f90 · schema v1 · pii pii-v1
Full breach record for Institute for Public Architecture →Public Architecture disclosed that its website, theonepercent.org, was hacked on December 8, 2014. An unauthorized actor exploited security vulnerabilities to deface the site with a vanity page and delete essential files. The organization suspects that user information, including usernames, passwords, and contact details, may have been stolen. The vulnerabilities were patched, the defacement removed, and law enforcement was notified. Users were advised to monitor their accounts for suspicious activity.
California clockDiscovered Dec 8, 2014 → Notified Dec 17, 20149d ✓ CA 60-day OK15 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-47847
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2014
- Raw hash
- b6e0e04b899853bbafb4b0009ca8ffc9de42520b2347296c0e48081c63531325
Reporting entity
- Name
- Public Architecturenorm: public architecture
Victim entity
- Name
- Institute for Public Architecturenorm: institute for public architecture
- Domain
- instituteforpublicarchitecture.org
Incident
- Discovered
- Dec 8, 2014
- Materiality determined
- —
- Notification sent
- Dec 17, 2014
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 9d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 8, 2014→ Notified: Dec 17, 20149d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.