HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
GFS
bd_e34e73f5b176fa0c · schema v1 · pii pii-v1
Full breach record for GFS →GFS, Inc. notified California regulators of a data breach occurring between August 13 and 22, 2019. An unauthorized actor gained access to an office computer and used stolen credentials to file fraudulent tax returns. Personal information including names, SSNs, and financial data was exposed. GFS engaged forensic investigators, notified the IRS, and provided credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-184304
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2019
- Raw hash
- 5bbe344584d3bce011f065b2a453d779ca3a5098b0ceddf68a7e0d6130bb01f1
Reporting entity
- Name
- GFSnorm: gfs
- Domain
- gfsinc.net
Victim entity
- Name
- GFSnorm: gfs
- Domain
- gfsinc.net
Incident
- Discovered
- Aug 20, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to the IRS
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.