MisusePrivilege AbuseEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
California Department of Social Services
bd_c0bcaa1f4bb4192b · schema v1 · pii pii-v1
Full breach record for California Department of Social Services →The California Department of Social Services (CDSS) disclosed that employees of a contractor operating the Sun Bucks call center improperly accessed case information in the ebtEDGE Web Admin platform between June 6 and June 18, 2024. The breach was discovered on July 19, 2024. Affected data included children's names, addresses, dates of birth, EBT card numbers, and account numbers. CDSS terminated the employees' access, compensated for lost benefits, issued new cards, and offered identity protection services.
California clockDiscovered Jul 19, 2024 → Notified Sep 27, 202470d ✗ CA 60-day late11 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-592849
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2024
- Raw hash
- a90a9f74cae3f66098dfb7d241c19f2e24fa922058c3730fbbd3e3c4ae0ab449
Reporting entity
- Name
- California Department of Social Servicesnorm: california department of social
Victim entity
- Name
- California Department of Social Servicesnorm: california department of social
Incident
- Discovered
- Jul 19, 2024
- Materiality determined
- —
- Notification sent
- Sep 27, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Partner
- Regulator citations
- Reported to the California Information Security Office
- Third party
- via Sun Bucks call center contractor
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- CA 60-day late · 70d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 19, 2024→ Notified: Sep 27, 202470d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.