State Controller's Office
bd_d410929ef5d4c6a3 · schema v1 · pii pii-v1
Full breach record for State Controller's Office →The California State Controller's Office experienced a data breach after an employee clicked a phishing link, granting an unauthorized user access to their email account from March 18-19, 2021. The attacker accessed Unclaimed Property Holder Reports containing names, addresses, SSNs, birth dates, and property values. Access was promptly removed, and 24 months of identity theft resolution services were offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 18, 2021
Begins
Mar 19, 2021
Discovered
Mar 23, 2021
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.