Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIALMediumContained
County of Los Angeles Department of Public Health
bd_fb3486d265df333d · schema v1 · pii pii-v1
Full breach record for County of Los Angeles Department of Public Health →Los Angeles County Dept of Public Health experienced a phishing attack between Feb 19-20, 2024, where an external actor gained credentials for 53 employees via a malicious link. Compromised data may include names, DOB, SSN, diagnoses, prescriptions, medical record numbers, and insurance info. DPH disabled accounts, reset devices, and offered one year of identity monitoring via Kroll. Law enforcement was notified.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586968
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 14, 2024
- Raw hash
- ece9f5748135d9ae458e8079984a8bf2d74a3dc3c195f728df30bd9083d26ced
Reporting entity
- Name
- County of Los Angeles Department of Public Healthnorm: county of los angeles department of public health
- Domain
- dph.lacounty.gov
Victim entity
- Name
- County of Los Angeles Department of Public Healthnorm: county of los angeles department of public health
- Domain
- dph.lacounty.gov
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Will notify the U.S. Department of Health & Human Services’ Office for Civil Rights and other agencies as required by law and/or contract
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.