Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
County Of Orange
bd_fbb4a4e177064195 · schema v1 · pii pii-v1
Full breach record for County Of Orange →The County of Orange Office of Care Coordination experienced a data breach after an employee's email account was compromised via a suspected phishing attack on January 31, 2023. The incident potentially exposed names, addresses, dates of birth, and Social Security numbers. The County secured the account, reset credentials, implemented MFA, and engaged a forensic firm. Affected individuals are offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-609898
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 12, 2025
- Raw hash
- 0b719f589706663f26e77127c21e5aa59a2ae447b79917c90c25658b4f7f60dc
Reporting entity
- Name
- County Of Orangenorm: county of orange
Victim entity
- Name
- County Of Orangenorm: county of orange
Incident
- Discovered
- Jan 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Filed notification with California Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 32 months(955 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.