HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIMediumContained
Employer Leasing Company
bd_c00a5ba7b0b76721 · schema v1 · pii pii-v1
Full breach record for Employer Leasing Company →Employer Leasing Company reported a data breach in California where files containing sensitive employee information (names, SSNs, driver's licenses, health insurance info) were made publicly accessible via Google search between Sept 14-18, 2017. The company discovered the issue on Oct 17, 2017, engaged forensic investigators, and notified 817 California residents. No evidence of misuse was found. Remediation included credit monitoring and identity restoration services.
California clockDiscovered Oct 17, 2017 → Notified Nov 7, 201721d ✓ CA 60-day OK13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_31cdf47ba61c240cMontana State AGfiled 2018-01-18Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-132930
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 18, 2018
- Raw hash
- d6e80d4881ae1b52ac3de538e4b970580c775198451f977463181eb994b61e74
Reporting entity
- Name
- Employer Leasing Companynorm: employer leasing
Victim entity
- Name
- Employer Leasing Companynorm: employer leasing
Incident
- Discovered
- Oct 17, 2017
- Materiality determined
- —
- Notification sent
- Nov 7, 2017
- Affected individuals
- 817
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Provided notice to the California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 17, 2017→ Notified: Nov 7, 201721d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.