HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Citrus Health Network
bd_fbab2208beac735f · schema v1 · pii pii-v1
Full breach record for Citrus Health Network →Citrus Valley Health Partners notified the California AG of a data breach involving third-party vendor Jobscience. An unauthorized third party accessed Jobscience's server around May 8, 2018, exfiltrating applicant data including names, SSNs, DOBs, driver's licenses, and alien registration numbers. Jobscience remediated the server and offered 12 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-142668
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2018
- Raw hash
- 150c84fcf5b92fbb8321259971bf01671a5ad61e5ac77381ea56f161bb98c505
Reporting entity
- Name
- Citrus Health Networknorm: citrus health network
- Domain
- citrushealth.org
Victim entity
- Name
- Citrus Health Networknorm: citrus health network
- Domain
- citrushealth.org
Incident
- Discovered
- Sep 5, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Law enforcement is aware of the incident
- Third party
- via Jobscience
- Initial access
- supply_chain
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.