Clustered 4 filings across 4 jurisdictions · filing window Feb 27, 2026 → Mar 3, 2026. View entity profile → Other incidents for this victim →
incident inc_37d282c4f1244b39 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
PII · Government ID · Health (basic)
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA ME NH VT
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Aug 1, 2025
When the intrusion reportedly occurred, per the linked filings
Aug 3, 2025
Reported by CALIFORNIA AG, VERMONT AG, NEW HAMPSHIRE AG filings
Feb 23, 2026
Reported by MAINE AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Children's Council of San Francisco experienced a data security incident where an unknown actor accessed and acquired personal information, including names and Social Security numbers. The breach occurred on August 1, 2025, and was discovered on August 3, 2025, following a network disruption. The organization secured its network, engaged cybersecurity experts, and notified the FBI. Affected individuals are offered credit monitoring and identity theft protection services.
Children's Council of San Francisco, a San Francisco-based non-profit, experienced a network disruption on August 3, 2025. An unknown external actor accessed and acquired data without authorization. Affected data included names combined with Social Security numbers. The incident was discovered on February 23, 2026. One Maine resident was among 12,655 total individuals affected. The organization notified the FBI and offered 12-month credit monitoring through TransUnion/Cyberscout.
Affected (this filing): 1
Children's Council of San Francisco disclosed a data breach occurring on August 3, 2025, where an unknown actor accessed personal information including names and Social Security Numbers. The organization engaged forensic experts, notified the FBI, and offered 12 months of credit monitoring and identity theft protection via TransUnion/Cyberscout. Notification was sent in February 2026.
Children’s Council of San Francisco, a California non-profit, notified the New Hampshire Attorney General of a data security incident affecting one NH resident. Unauthorized access occurred on or about August 1, 2025, involving the resident's name and Social Security Number. The Council engaged cybersecurity experts, reported the incident to the FBI, and sent notification letters offering 12 months of credit monitoring and identity theft protection services.
Affected (this filing): 1