HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
The Grand Lodge of Free & Accepted Masons of California
bd_f6a89cd286e31628 · schema v1 · pii pii-v1
Full breach record for The Grand Lodge of Free & Accepted Masons of California →The Grand Lodge of Free & Accepted Masons of California notified individuals of a data breach involving unauthorized access to an employee email account. The incident, discovered on June 14, 2022, potentially exposed names, signatures, and financial account information from donation checks sent between March 2020 and June 2022. The organization reset passwords, engaged forensic investigators, and offered 12 months of credit monitoring.
California clockDiscovered Jun 14, 2022 → Notified Aug 19, 202266d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_33978a6670ab5b5dMontana State AGfiled 2022-08-19Candidate
- bd_559b05b09bfd3c2fMaine State AGfiled 2022-08-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556409
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 19, 2022
- Raw hash
- 1e7f49d9f8ef9dd4545110d537e73b93cdce8a80bbd33bb6c926670182b57f3e
Reporting entity
- Name
- The Grand Lodge of Free & Accepted Masons of Californianorm: the grand lodge of free accepted masons of california
Victim entity
- Name
- The Grand Lodge of Free & Accepted Masons of Californianorm: the grand lodge of free accepted masons of california
Incident
- Discovered
- Jun 14, 2022
- Materiality determined
- —
- Notification sent
- Aug 19, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- CA 60-day late · 66d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 14, 2022→ Notified: Aug 19, 202266d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.