Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Volunteers of America Southwest California
bd_e2f6d535497a8868 · schema v1 · pii pii-v1
Full breach record for Volunteers of America Southwest California →Volunteers of America Southwest experienced a phishing incident on November 16, 2021, when an employee clicked a malicious link in an email appearing to be from a voicemail service. The attacker used the employee's credentials to access internal financial processes and limited client information, including names and COVID vaccination status. No SSNs or payment card data were involved. The organization contained the incident, reset passwords, and engaged outside experts.
California clockDiscovered Nov 16, 2021 → Notified Jan 14, 202259d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b0dde45c3b1b91edHHS OCRfiled 2022-01-14Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-550020
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2022
- Raw hash
- 8c52789f0e036a1a64f97c53eacd770a68664fe814ce896f95ebea559b1a3c2e
Reporting entity
- Name
- Volunteers of America Southwest Californianorm: volunteers of america southwest california
Victim entity
- Name
- Volunteers of America Southwest Californianorm: volunteers of america southwest california
Incident
- Discovered
- Nov 16, 2021
- Materiality determined
- —
- Notification sent
- Jan 14, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 16, 2021→ Notified: Jan 14, 202259d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.