AccidentalMisconfigurationSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMINORMediumResolved
CSAC-EXCESS INSURANCE AUTHORITY
bd_f923cf2bdda82af8 · schema v1 · pii pii-v1
Full breach record for CSAC-EXCESS INSURANCE AUTHORITY →CSAC-Excess Insurance Authority notified the California AG of a breach involving its third-party vendor, Systema Software. A security researcher identified a configuration error in Systema's claims management website that allowed access to a temporary data backup. The researcher self-reported the issue to the Texas AG. Affected data included names, SSNs, driver's license numbers, and medical information. No unauthorized use was believed to have occurred.
California clockDiscovered Sep 9, 2015 → Notified Nov 10, 201562d ✗ CA 60-day late9 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-58732
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 10, 2015
- Raw hash
- 5fa520e69615924e7c02bcefdcb6f3b024d0e442bf75ea9e1a818bec99302898
Reporting entity
- Name
- CSAC-EXCESS INSURANCE AUTHORITYnorm: csac excess insurance authority
Victim entity
- Name
- CSAC-EXCESS INSURANCE AUTHORITYnorm: csac excess insurance authority
Incident
- Discovered
- Sep 9, 2015
- Materiality determined
- —
- Notification sent
- Nov 10, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMINOR
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified California Attorney GeneralNotified Texas Attorney General
- Third party
- via Systema Software
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 9, 2015→ Notified: Nov 10, 201562d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.