HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTHighContained
Welk Resort Group, Inc.
bd_e90ad8f5a5b8cb35 · schema v1 · pii pii-v1
Full breach record for Welk Resort Group, Inc. →Welk Resort Group, Inc. reported a data event in California involving unauthorized access to an employee email account between July 24, 2018, and August 2, 2018. The breach affected approximately 1,320 California residents, exposing personal information including names, SSNs, driver's license numbers, medical data, and financial account numbers. No evidence of misuse was found. The company engaged forensic investigators and provided 12 months of credit monitoring to affected individuals.
California clockDiscovered Aug 2, 2018 → Notified Feb 22, 2019204d ✗ CA 60-day late29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7c42c8e0b49b0701Montana State AGfiled 2019-02-22Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144939
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 22, 2019
- Raw hash
- 94f638fd254d0cbfb33b5572fd595c1e4f787a4f18aa80fd289185b8ab27e035
Reporting entity
- Name
- Welk Resort Group, Inc.norm: welk resort
Victim entity
- Name
- Welk Resort Group, Inc.norm: welk resort
Incident
- Discovered
- Aug 2, 2018
- Materiality determined
- —
- Notification sent
- Feb 22, 2019
- Affected individuals
- 1,320
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Providing notice to other state regulators and credit reporting agencies as required by law
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 weeks(204 days from discovery to filing)
- Compliance flags
- CA 60-day late · 204d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 2, 2018→ Notified: Feb 22, 2019204d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.