HackingStolen CredentialsEmployee Data InvolvedIDENTITY_BASICLowContained
Housing Authority of the County of San Bernardino
bd_de2d36b21007fc2a · schema v1 · pii pii-v1
Full breach record for Housing Authority of the County of San Bernardino →The Housing Authority of the County of San Bernardino notified the California Attorney General of an incident involving unauthorized access to one employee email account. The breach occurred between May 19, 2023, and June 26, 2023, and was discovered on June 19, 2023. The potentially accessed information included names and other personal data elements. The organization reset the password, engaged forensic investigators, and secured the email tenant. Complimentary credit monitoring was offered to affected individuals.
California clockDiscovered Jun 19, 2023 → Notified Jan 2, 2024197d ✗ CA 60-day late28 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3d50aebe2c4e8019New Hampshire State AGfiled 2024-01-03Verified
- bd_7287adc2de377fe0Montana State AGfiled 2024-01-03Candidate
- bd_c794c4e88c630312Maine State AGfiled 2024-01-04(1d gap)Verified by operator
- bd_405152691464335aVermont State AGfiled 2024-01-02(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_a061da6246ee57fbIndiana State AGfiled 2024-01-02(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578810
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 3, 2024
- Raw hash
- 1d3bd45c5145cda82194e1b3264995f57da89f4f49adf6202f0851caff4d1f34
Reporting entity
- Name
- Housing Authority of the County of San Bernardinonorm: housing authority of the county of san bernardino
Victim entity
- Name
- Housing Authority of the County of San Bernardinonorm: housing authority of the county of san bernardino
Incident
- Discovered
- Jun 19, 2023
- Materiality determined
- —
- Notification sent
- Jan 2, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 weeks(198 days from discovery to filing)
- Compliance flags
- CA 60-day late · 197d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 19, 2023→ Notified: Jan 2, 2024197d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.