HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
State Bar of Georgia
bd_c756708edd2c77ef · schema v1 · pii pii-v1
Full breach record for State Bar of Georgia →The State Bar of Georgia experienced a cybersecurity incident resulting in unauthorized access to systems containing personal information of current and former employees and members. The breach, occurring on or about April 28, 2022, exposed names, addresses, dates of birth, Social Security numbers, driver's license numbers, and direct deposit information. The State Bar engaged third-party investigators, notified law enforcement, and offered credit monitoring and identity protection services to affected individuals.
Leak gap clock⏱ Leak >90d≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 4 about the same incident.View merged incident
A leak claim by bitlocker about this victim predates this filing by 158 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0ce6a596caf01769Leak Sitebitlockerfiled 2022-05-02(158d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_5f352d5e00d31e80Maine State AGfiled 2022-10-07Verified
- bd_ada264b59572b165Montana State AGfiled 2022-10-07Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557991
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 7, 2022
- Raw hash
- 2dcca96fa0293084efecc69053f51fe3addddcea6ebcb5f966b0b103cf369246
Reporting entity
- Name
- State Bar of Georgianorm: state bar of georgia
- Industry
- professional_services
Victim entity
- Name
- State Bar of Georgianorm: state bar of georgia
- Industry
- professional_services
Incident
- Discovered
- Oct 7, 2022
- Materiality determined
- —
- Notification sent
- Oct 7, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- regulators were notified
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- Leak >90dCA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 7, 2022→ Notified: Oct 7, 20220d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.