HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
CREDIT UNION OF SOUTHERN CALIFORNIA
bd_bcc967111ff13a78 · schema v1 · pii pii-v1
Full breach record for CREDIT UNION OF SOUTHERN CALIFORNIA →Credit Union of Southern California (CU SoCal) notified the California Attorney General of unauthorized access to a CalBear employee email account between January 11 and January 31, 2023. CU SoCal became aware of suspicious activity on January 31, 2023. The investigation confirmed unauthorized access but could not confirm if emails were read. Potentially impacted information includes names and other personal data. CU SoCal secured the account, engaged forensic specialists, reset passwords, enhanced training, and offered 24 months of credit monitoring.
California clockDiscovered Jan 31, 2023 → Notified May 26, 2023115d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8f27d1346d2ebeffCalifornia State AGfiled 2023-05-18(14d gap)Candidate
- bd_df0b12f39d31af62Vermont State AGfiled 2023-05-18(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567478
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2023
- Raw hash
- 48373c7714e335c58f7137bea0981be070efc3ec48ab3bca6a53801095856aa0
Reporting entity
- Name
- CREDIT UNION OF SOUTHERN CALIFORNIAnorm: credit union of southern california
Victim entity
- Name
- CREDIT UNION OF SOUTHERN CALIFORNIAnorm: credit union of southern california
Incident
- Discovered
- Jan 31, 2023
- Materiality determined
- —
- Notification sent
- May 26, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- CA 60-day late · 115d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 31, 2023→ Notified: May 26, 2023115d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.