HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMINORMediumContained
Trusteed Plan Services Corporation
bd_e877db61aece8a95 · schema v1 · pii pii-v1
Full breach record for Trusteed Plan Services Corporation →Trusteed Plans Service Corporation (TPSC) detected unauthorized access to its computer environment on December 26, 2024. An unauthorized user gained access and obtained personal information, including names, addresses, dates of birth, and Social Security numbers, of plan participants, their children, and deceased individuals. TPSC engaged third-party cybersecurity firms, disconnected network access, and changed credentials. The company is offering 12 months of cyber or credit monitoring services to affected individuals. No evidence of misuse has been found.
California clockDiscovered Dec 26, 2024 → Notified Sep 15, 2025263d ✗ CA 60-day late38 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_239543df911e11aeMaine State AGfiled 2025-09-15Verified
- bd_2784da27b9d22503Oregon State AGfiled 2025-09-15Verified
- bd_2fd6c2009f8f2fd3Montana State AGfiled 2025-09-15Verified
- bd_4bf1c9fac6cb9260Washington State AGfiled 2025-09-15Verified
Show 3 more filings ↓Show fewer ↑up to 7d gap
- bd_7865db4bd7dd399fIndiana State AGfiled 2025-09-15Verified
- bd_447f5e820983570cHHS OCRfiled 2025-09-17(2d gap)Verified
- bd_6bb953f8b0288db2New Hampshire State AGfiled 2025-09-22(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-609991
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2025
- Raw hash
- a7cdbfa80594dbf4fcd5b049a61e5a1e75d9afd6e01ab9680f91b369e0e2c89d
Reporting entity
- Name
- Trusteed Plan Services Corporationnorm: trusteed plan
Victim entity
- Name
- Trusteed Plan Services Corporationnorm: trusteed plan
Incident
- Discovered
- Dec 26, 2024
- Materiality determined
- —
- Notification sent
- Sep 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMINOR
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 38 weeks(263 days from discovery to filing)
- Compliance flags
- CA 60-day late · 263d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 26, 2024→ Notified: Sep 15, 2025263d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.