DisclosureLens
Social EngineeringGovernmentGovernmentPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

State Controller's Office

bd_d410929ef5d4c6a3 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 19, 2021

Filed

Mar 23, 2021

To disclose

4 days

Affected

Not disclosed

Confidence

65%
Full breach record for State Controller's Office

The California State Controller's Office experienced a data breach after an employee clicked a phishing link, granting an unauthorized user access to their email account from March 18-19, 2021. The attacker accessed Unclaimed Property Holder Reports containing names, addresses, SSNs, birth dates, and property values. Access was promptly removed, and 24 months of identity theft resolution services were offered to affected individuals.

California clockDiscovered Mar 19, 2021Notified Mar 22, 20212d CA 60-day OK4 days discovery → filing

Incident timeline

undetected · 1 days
discovery → filing · 3 days

Mar 18, 2021

Begins

Mar 19, 2021

Discovered

Mar 23, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.