HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIMediumContained
Visit California
bd_f462a044442ea673 · schema v1 · pii pii-v1
Full breach record for Visit California →California Cryobank LLC notified individuals of a data security incident where an unauthorized party accessed its IT environment between April 20-22, 2024. The incident potentially exposed names, Social Security numbers, driver's license numbers, financial account numbers, and health insurance information. The company isolated affected systems, conducted an investigation, and is offering 12 months of complimentary identity protection services through TransUnion.
Maryland clock✗ MD AG >90d47 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_36b1cb539cada28aIndiana State AGfiled 2025-03-14Verified
- bd_5d46b4ecbee67559Montana State AGfiled 2025-03-14Candidate
- bd_64dce7ff2645324aCalifornia State AGfiled 2025-03-14Verified
- bd_7981bf2586698512New Hampshire State AGfiled 2025-03-14Verified
Show 1 more filing ↓Show fewer ↑
- bd_98eddcd84ac7a1f9Vermont State AGfiled 2025-03-14Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376558.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2025
- Raw hash
- 473e6eca00d553e438ab97c5af5fcf36707711b4a8c5a800dc0e8ec0606a0d42
Reporting entity
- Name
- Visit Californianorm: visit california
- Domain
- visitcalifornia.com
Victim entity
- Name
- Visit Californianorm: visit california
- Domain
- visitcalifornia.com
Incident
- Discovered
- Apr 21, 2024
- Materiality determined
- —
- Notification sent
- Mar 14, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 47 weeks(327 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.