HackingStolen CredentialsPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Verity Medical Foundation
bd_e8b477fb6f2d1371 · schema v1 · pii pii-v1
Full breach record for Verity Medical Foundation →On November 28, 2018, Verity Medical Foundation reported that a third party compromised an employee's Microsoft 365 email account for approximately 1.5 hours. The attacker sent emails with malicious Docusign links to obtain credentials. The intruder had access to the employee's email folders, which contained personal information including names, dates of birth, social security numbers, phone numbers, and addresses. The Foundation terminated access, disabled the account, and offered one year of credit monitoring.
California clockDiscovered Nov 28, 2018 → Notified Jan 26, 201959d ✓ CA 60-day OK9 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144154
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 28, 2019
- Raw hash
- e96c5b96fd1a6e707f3c846414e3c6ca7f242bcf680a3159c2cbd6b98f2f4514
Reporting entity
- Name
- Verity Medical Foundationnorm: verity medical
- Domain
- sanjosemed.com
Victim entity
- Name
- Verity Medical Foundationnorm: verity medical
- Domain
- sanjosemed.com
Incident
- Discovered
- Nov 28, 2018
- Materiality determined
- —
- Notification sent
- Jan 26, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email CollectionT1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 28, 2018→ Notified: Jan 26, 201959d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.