Social EngineeringPhishingData ExfiltratedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ULTRA CLEAN HOLDINGS, INC.
bd_c786788ea3638551 · schema v1 · pii pii-v1
Full breach record for ULTRA CLEAN HOLDINGS, INC. →Ultra Clean Holdings, Inc. (UCT) notified California regulators of a phishing incident occurring August 3-4, 2020, discovered August 5, 2020. Attackers obtained personal information including names, addresses, and government IDs. UCT provided two years of Experian IdentityWorks monitoring. The attacker is a sophisticated criminal enterprise seeking extortion.
California clockDiscovered Aug 5, 2020 → Notified Oct 23, 202079d ✗ CA 60-day late20 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_5db3f2dc02d3ea4dMaine State AGfiled 2020-12-17(6d gap)Verified
- bd_10838ceb3c534737Oregon State AGfiled 2020-11-10(43d gap)Verified
- bd_9f16c0167e7bd358Maine State AGfiled 2020-10-23(61d gap)Candidate
- bd_e8e9dcedfef9c1c5Montana State AGfiled 2020-10-23(61d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197489
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2020
- Raw hash
- 68d80ade6f6e57b9293c374fa1d60db78414b35c91d81a2093ba1b1db4851eab
Reporting entity
- Name
- ULTRA CLEAN HOLDINGS, INC.norm: ultra clean
- Domain
- uct.com
Victim entity
- Name
- ULTRA CLEAN HOLDINGS, INC.norm: ultra clean
- Domain
- uct.com
Incident
- Discovered
- Aug 5, 2020
- Materiality determined
- —
- Notification sent
- Oct 23, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 20 weeks(140 days from discovery to filing)
- Compliance flags
- CA 60-day late · 79d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 5, 2020→ Notified: Oct 23, 202079d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.