CSAC-Excess Insurance Authority notified the California AG of a breach involving its third-party vendor, Systema Software. A security researcher identified a configuration error in Systema's claims management website that allowed access to a temporary data backup. The researcher self-reported the issue to the Texas AG. Affected data included names, SSNs, driver's license numbers, and medical information. No unauthorized use was believed to have occurred.