HackingData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
City of Torrance (Los Angeles County)
bd_d8ff1381ca0cea97 · schema v1 · pii pii-v1
Full breach record for City of Torrance (Los Angeles County) →The City of Torrance notified employees of a cybersecurity incident initially identified on March 1, 2020. On April 21, 2020, the City learned that employee data, including names, Social Security numbers, financial account information, and other government identification numbers, had been found on the internet. The investigation remains ongoing with law enforcement and cybersecurity professionals. The City is offering one year of complimentary identity protection services through Experian.
California clockDiscovered Mar 1, 2020 → Notified May 15, 202075d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d82eb43ce1b2e163Leak Sitedoppelpaymerfiled 2020-03-01(78d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_af935553dc09ee0bMontana State AGfiled 2020-10-13(148d gap)Verified by operator
- bd_16c8e764e7e05e93California State AGfiled 2020-10-18(153d gap)Verified by operator
- bd_2b3c67d52d445c28Maine State AGfiled 2020-10-18(153d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190118
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2020
- Raw hash
- b851f3c0d5c3ad229da34e53cc3b9b0b6453f74be0dbc14abd4fc11a5ed81d50
Reporting entity
- Name
- City of Torrance (Los Angeles County)norm: city of torrance los angeles county
Victim entity
- Name
- City of Torrance (Los Angeles County)norm: city of torrance los angeles county
Incident
- Discovered
- Mar 1, 2020
- Materiality determined
- —
- Notification sent
- May 15, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- CA 60-day late · 75d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 1, 2020→ Notified: May 15, 202075d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.