HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Authentic Recovery Center, LLC
bd_ed0427fd5fd16842 · schema v1 · pii pii-v1
Full breach record for Authentic Recovery Center, LLC →Authentic Recovery Center, LLC reported a data breach affecting California residents. An unauthorized third party gained access to a secure email account between June 7, 2018, and June 21, 2018. Exposed data included names, client status, limited clinical information, driver's license numbers, and payment card information. No Social Security numbers were exposed. The company notified authorities, terminated access, and offered 12 months of identity theft protection.
California clockDiscovered Jun 21, 2018 → Notified Aug 15, 201855d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_bc627897c1f9c72dHHS OCRfiled 2018-08-17Verified
- bd_363b7dfaab0a7f09Montana State AGfiled 2018-08-15(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-138972
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2018
- Raw hash
- fd9995b7ffcc746fdb6ff05cddc2200adb2001ee741fbbed5637073efc7fddc9
Reporting entity
- Name
- Authentic Recovery Center, LLCnorm: authentic recovery center
Victim entity
- Name
- Authentic Recovery Center, LLCnorm: authentic recovery center
Incident
- Discovered
- Jun 21, 2018
- Materiality determined
- —
- Notification sent
- Aug 15, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified local and federal authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 55d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 21, 2018→ Notified: Aug 15, 201855d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.