HackingData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumActive
Covina-Valley Unified School District (Los Angeles County, California)
bd_decf76d6d393b4fb · schema v1 · pii pii-v1
Full breach record for Covina-Valley Unified School District (Los Angeles County, California) →Los Angeles Unified School District notified the California Attorney General of a cyberattack involving unauthorized access to its network between July 31, 2022, and September 3, 2022. An unauthorized actor accessed and acquired labor compliance documents, including certified payroll records, containing names, addresses, and Social Security numbers of contractor and subcontractor employees. The district secured systems, notified law enforcement, and is offering identity protection services.
Leak gap clock⏱ Leak >90d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d73fcc8603946a6aLeak Sitevicesocietyfiled 2022-09-30(109d gap)Verified by operator
Regulatory filings (1) · sorted by filing gap
- bd_45725dc7d023d3f3California State AGfiled 2023-03-24(66d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-561863
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 17, 2023
- Raw hash
- d3c1425d941d1980c4694497fbf3576477b6a1384db58994d866a61b8cdbb6a8
Reporting entity
- Name
- Covina-Valley Unified School District (Los Angeles County, California)norm: covina valley unified school district los angeles county california
Victim entity
- Name
- Covina-Valley Unified School District (Los Angeles County, California)norm: covina valley unified school district los angeles county california
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Compliance flags
- Leak >90d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.