HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Keolis Transit America, Inc.
bd_cfa2089146ff0aa2 · schema v1 · pii pii-v1
Full breach record for Keolis Transit America, Inc. →Keolis Transit America, a subsidiary of Keolis North America, disclosed a data breach involving a physical USB thumb drive found in a laundromat. The drive contained spreadsheets with personal information of current and former employees, including names, addresses, SSNs, financial account numbers, and limited medical data (pregnancy status, COVID test results). The incident occurred between January 4, 2021, and May 23, 2021. Keolis engaged forensic experts and offered 12 months of identity monitoring services via Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548188
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 3, 2021
- Raw hash
- bf55a69656287357c430f725dc0d7320e0109b7b0b802dc09bd2a940e12c5db7
Reporting entity
- Name
- Keolis Transit America, Inc.norm: keolis transit america
Victim entity
- Name
- Keolis Transit America, Inc.norm: keolis transit america
Incident
- Discovered
- May 23, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1535 Unused or Untrusted Cloud Storage
- Threat actor
- External
Compliance
- Time to disclose
- 28 weeks(194 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.