CHP 11-99 Foundation
ent_06749b1a0b77d13bc956d599
Disclosures
3
State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHP 11-99 Foundation
- Normalized
- chp 11 99— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- 🐻California State AGas victim2026-01-23
CHP 11-99 Foundation experienced a data breach after a staff member clicked a malicious link in a phishing email on September 16, 2025, despite initial clearance from a third-party help desk. The attacker gained access to the staff member's email account, potentially exposing membership applications, payment forms, bank/credit card info, SSNs, and driver's license numbers. The incident was discovered on September 24, 2025, when the attacker attempted to phish the help desk. The organization has implemented MFA, changed passwords, and engaged an incident response vendor. Identity monitoring services are being provided to affected individuals.
- ⛰️New Hampshire State AGas victim2026-01-20
CHP 11-99 Foundation notified the New Hampshire Attorney General of a data incident affecting one NH resident. A staff member clicked a phishing link on September 16, 2025, after a third-party help desk incorrectly cleared it. The attacker accessed the staff member's email, exposing membership applications, payment forms (bank/credit card info), names, addresses, and SSNs. The foundation is working with incident response vendors, implemented MFA, changed passwords, and plans to change its IT provider. Notification to the resident was scheduled for January 30, 2026.
- 🐻California State AGas victim2025-09-16
On or about September 16, 2025, a CHP 11-99 Foundation staff member clicked a phishing link after an external service provider's Help Desk incorrectly cleared it as safe. The attacker gained full access to the staff member's email account, including membership applications and payment documents containing bank/credit card information, driver's license numbers, Social Security numbers, names, addresses, and email addresses. Discovery occurred on September 24, 2025, when the attacker attempted to use the compromised account to phish the Help Desk.