BenefitsCal (California Statewide Automated Welfare System) disclosed that an unauthorized party accessed user accounts using reused passwords obtained from other websites. The incident occurred between March 1, 2023, and February 13, 2024, and was discovered on February 9, 2024. Affected data included names, addresses, SSNs, EBT card numbers, and Medi-Cal IDs. BenefitsCal temporarily inactivated accounts, enforced multi-factor authentication, and reissued EBT cards.