HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Children's Council of San Francisco
bd_f70372d1a991c750 · schema v1 · pii pii-v1
Full breach record for Children's Council of San Francisco →Children's Council of San Francisco experienced a data security incident where an unknown actor accessed and acquired personal information, including names and Social Security numbers. The breach occurred on August 1, 2025, and was discovered on August 3, 2025, following a network disruption. The organization secured its network, engaged cybersecurity experts, and notified the FBI. Affected individuals are offered credit monitoring and identity theft protection services.
California clockDiscovered Aug 3, 2025 → Notified Feb 27, 2026208d ✗ CA 60-day late30 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_13cc3591bebd9bb2Maine State AGfiled 2026-03-03(4d gap)Verified by operator
- bd_ac66c0f72cc2eaf3Vermont State AGfiled 2026-03-03(4d gap)Verified
- bd_d544b6922b9ab320New Hampshire State AGfiled 2026-03-03(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619614
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2026
- Raw hash
- b41335bb9b9df0b991fb8fb8f4e3044fe4f6d206a584ab0a2bcf51f4d654acc0
Reporting entity
- Name
- Children's Council of San Francisconorm: children s council of san francisco
Victim entity
- Name
- Children's Council of San Francisconorm: children s council of san francisco
Incident
- Discovered
- Aug 3, 2025
- Materiality determined
- —
- Notification sent
- Feb 27, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
Compliance
- Time to disclose
- 30 weeks(208 days from discovery to filing)
- Compliance flags
- CA 60-day late · 208dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 3, 2025→ Notified: Feb 27, 2026208d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Feb 27, 2026→ AG copy submitted: Feb 27, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.