HackingStolen CredentialsEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
City College of San Francisco
bd_c98950552cb6a748 · schema v1 · pii pii-v1
Full breach record for City College of San Francisco →City College of San Francisco reported that an unauthorized individual accessed an employee's email account containing personal information of students and employees. The breach occurred on February 11, 2019, and was discovered on April 18, 2019. Affected data includes names, addresses, dates of birth, and potentially Social Security numbers. The college changed passwords, disabled self-service direct deposit changes, engaged forensic investigators, and offered one year of identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148422
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 25, 2019
- Raw hash
- 4025be64561c3ac1dd95c0bd93f815aea939e04e9af0ef3f9b0916f52babf18b
Reporting entity
- Name
- City College of San Francisconorm: city college of san francisco
- Domain
- ccsf.community.highbond.com
Victim entity
- Name
- City College of San Francisconorm: city college of san francisco
- Domain
- ccsf.community.highbond.com
Incident
- Discovered
- Apr 18, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.