On or about September 16, 2025, a CHP 11-99 Foundation staff member clicked a phishing link after an external service provider's Help Desk incorrectly cleared it as safe. The attacker gained full access to the staff member's email account, including membership applications and payment documents containing bank/credit card information, driver's license numbers, Social Security numbers, names, addresses, and email addresses. Discovery occurred on September 24, 2025, when the attacker attempted to use the compromised account to phish the Help Desk.