PeopleGuru Holdings, Inc.
bd_f7302e7c0355b774 · schema v1 · pii pii-v1
Full breach record for PeopleGuru Holdings, Inc. →PeopleGuru Holdings, Inc. notified the California Attorney General of a cybersecurity event where an unauthorized third party accessed network systems between July 6 and July 9, 2025. The company became aware of the incident on July 9, 2025. Affected data may include names, Social Security numbers, financial account information, dates of birth, passport numbers, driver's license numbers, medical information, and health insurance information. The company secured the network, investigated the incident, and is offering 12 months of credit monitoring and identity restoration services via TransUnion. Approximately 500 Rhode Island residents were also impacted.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0784df0b4b5da3a8Vermont State AGfiled 2025-10-16Verified
- bd_0db930842d8375a2New Hampshire State AGfiled 2025-10-16Verified
- bd_362524c5e6273d1eOregon State AGfiled 2025-10-16Candidate
- bd_6b4c088fda1aae18Iowa State AGfiled 2025-10-16Verified
Show 3 more filings ↓Show fewer ↑
- bd_7bc498b6d4233e97Montana State AGfiled 2025-10-16Verified
- bd_9cb66c5f7c9d9dfeWashington State AGfiled 2025-10-16Verified
- bd_d01f13524ff1165dMaine State AGfiled 2025-10-16Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-612889
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 16, 2025
- Raw hash
- bd3d5afd4a3d01fe0b4866eb0c3025b709184d8ebcf1f12aa2206ea87810338c
Reporting entity
- Name
- PeopleGuru Holdings, Inc.norm: peopleguru holdings
Victim entity
- Name
- PeopleGuru Holdings, Inc.norm: peopleguru holdings
Incident
- Discovered
- Jul 9, 2025
- Materiality determined
- —
- Notification sent
- Oct 16, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 14 weeks(99 days from discovery to filing)
- Compliance flags
- CA 60-day late · 99d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 9, 2025→ Notified: Oct 16, 202599d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.