The California Office of the Attorney General reported a data breach involving the Los Angeles County Department of Health Services (DHS) on April 25, 2024. The breach occurred between February 19, 2024, and February 20, 2024, due to a phishing attack that compromised the email accounts of 23 employees, potentially exposing personally identifiable information and health information, but not Social Security Numbers or financial data.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-584405
TPRM report: https://www.rankiteo.com/company/lahealthservices
"id": "lah435072725",
"linkid": "lahealthservices",
"type": "Breach",
"date": "2/2024",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'Los Angeles, California',
'name': 'Los Angeles County Department of Health '
'Services',
'type': 'Government Agency'}],
'attack_vector': 'Phishing',
'data_breach': {'personally_identifiable_information': True,
'type_of_data_compromised': ['Personally Identifiable '
'Information',
'Health Information']},
'date_detected': '2024-02-19',
'date_publicly_disclosed': '2024-04-25',
'description': 'The California Office of the Attorney General reported a data '
'breach involving the Los Angeles County Department of Health '
'Services (DHS) on April 25, 2024. The breach occurred between '
'February 19, 2024, and February 20, 2024, due to a phishing '
'attack that compromised the email accounts of 23 employees, '
'potentially exposing personally identifiable information and '
'health information, but not Social Security Numbers or '
'financial data.',
'impact': {'data_compromised': ['Personally Identifiable Information',
'Health Information']},
'initial_access_broker': {'entry_point': 'Email Account Compromise'},
'references': [{'date_accessed': '2024-04-25',
'source': 'California Office of the Attorney General'}],
'title': 'Data Breach at Los Angeles County Department of Health Services',
'type': 'Data Breach',
'vulnerability_exploited': 'Email Account Compromise'}