HackingEmployee Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
AECOM
bd_cc1fa549bcd5514a · schema v1 · pii pii-v1
Full breach record for AECOM →AECOM Technology Corporation disclosed a computer security attack resulting in the possible exposure of employee records. The incident affected present and past U.S. employees, potentially exposing names, addresses, Social Security numbers, and personal bank account numbers and routing information. AECOM engaged AllClear ID to provide 12 months of identity protection services to affected individuals.
California clockDiscovered Jun 7, 2014 → Notified Jul 7, 201430d ✓ CA 60-day OK4 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-45812
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2014
- Raw hash
- 29da654ec87a5f3278a9e716713e1021aacc31f50a55e3381ec47206ac3ffa32
Reporting entity
- Name
- AECOMnorm: aecom
- Domain
- aecom.jobs
Victim entity
- Name
- AECOMnorm: aecom
- Domain
- aecom.jobs
Incident
- Discovered
- Jun 7, 2014
- Materiality determined
- —
- Notification sent
- Jul 7, 2014
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 7, 2014→ Notified: Jul 7, 201430d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.