HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedCREDENTIALSIDENTITY_BASICLowContained
Braingenie
bd_f411ce56e9292ea9 · schema v1 · pii pii-v1
Full breach record for Braingenie →CK-12 Foundation (operating Braingenie) reported an unauthorized access to its QA/test database occurring in late February 2020, discovered in early June 2020. Unauthorized actors obtained a small amount of personal information, including user login credentials (username/email and encrypted passwords, potentially decrypted). The incident was limited to a subset of users. CK-12 engaged forensic experts and law enforcement, reset passwords, and enhanced security protocols.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-192443
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2020
- Raw hash
- fa0b6210b2c08b2b82120443b4be3e09b191c4330a15284e9b37f83c85c0ee2c
Reporting entity
- Name
- CK-12 Foundationnorm: ck 12
Victim entity
- Name
- Braingenienorm: braingenie
- Domain
- braingenie.ck12.org
Incident
- Discovered
- Feb 26, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- cooperating with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(152 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.