CSAC-EXCESS INSURANCE AUTHORITY
bd_f923cf2bdda82af8 · schema v1 · pii pii-v1
Full breach record for CSAC-EXCESS INSURANCE AUTHORITY →CSAC-Excess Insurance Authority notified the California AG of a breach involving its third-party vendor, Systema Software. A security researcher identified a configuration error in Systema's claims management website that allowed access to a temporary data backup. The researcher self-reported the issue to the Texas AG. Affected data included names, SSNs, driver's license numbers, and medical information. No unauthorized use was believed to have occurred.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 3, 2015
Begins
Sep 9, 2015
Discovered
Nov 10, 2015
Filed
vs. sector median
on median
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.