AccidentalMisconfigurationEmployee Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
California Department of Food and Agriculture
bd_d63477e4455e520e · schema v1 · pii pii-v1
Full breach record for California Department of Food and Agriculture →California Department of Food and Agriculture (CDFA) reported a data breach on its Plant Health and Pest Prevention Services extranet site occurring on or around March 4, 2024. The incident exposed Personally Identifiable Information (PII) including names, addresses, phone numbers, email addresses, and site usernames and passwords. The agency identified and corrected the vulnerability. Affected individuals were advised to change their passwords.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582925
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2024
- Raw hash
- 9bb9637c0496c2c65195dddb03b59bd22d4cdf6b7da1d607b78691786a893e6c
Reporting entity
- Name
- California Department of Food and Agriculturenorm: california department of food and agriculture
Victim entity
- Name
- California Department of Food and Agriculturenorm: california department of food and agriculture
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.