HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
City of Indio/Indio Water Authority
bd_e87aef691b9d3cf0 · schema v1 · pii pii-v1
Full breach record for City of Indio/Indio Water Authority →The City of Indio/Indio Water Authority experienced a data breach involving its third-party payment vendor, Click2Gov. Unauthorized access occurred between January 1, 2017, and August 13, 2018, potentially exposing customer names, payment card numbers, expiration dates, and security codes. The authority shut down the payment system, engaged forensic investigators, and enhanced security protocols.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-140696
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 12, 2018
- Raw hash
- cc6e40c375f3a2ebfbdbbd64d760c9965ec6bc1d14573457f377385a486c0bd5
Reporting entity
- Name
- City of Indio/Indio Water Authoritynorm: city of indio indio water authority
Victim entity
- Name
- City of Indio/Indio Water Authoritynorm: city of indio indio water authority
Incident
- Discovered
- Aug 13, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.