The California Office of the Attorney General disclosed a data breach affecting Operating Engineers Local Union No. 3 on February 15, 2017, with the incident occurring on February 9, 2017. The breach exposed usernames, passwords, and email addresses of union website users. However, investigations found no evidence of unauthorized acquisition or misuse of personal data, meaning sensitive information such as financial records, Social Security numbers, or other high-risk personal details remained secure. The exposed credentials, while potentially exploitable for phishing or credential-stuffing attacks, did not lead to broader data compromise or financial harm. The union likely implemented password resets and security notifications as a precautionary measure, but the incident did not escalate into a larger-scale data theft or operational disruption. The breach was contained to non-sensitive account information, minimizing its overall impact on affected individuals and the organization.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-66363
TPRM report: https://www.rankiteo.com/company/operatingengineerslocalunion3
"id": "ope354090725",
"linkid": "operatingengineerslocalunion3",
"type": "Breach",
"date": "2/2017",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Construction / Labor',
'location': 'California, USA',
'name': 'Operating Engineers Local Union No. 3',
'type': 'Labor Union'}],
'data_breach': {'personally_identifiable_information': 'No evidence of PII '
'compromise',
'sensitivity_of_data': 'Low (no evidence of unauthorized '
'acquisition of personal data)',
'type_of_data_compromised': ['credentials',
'contact information']},
'date_detected': '2017-02-09',
'date_publicly_disclosed': '2017-02-15',
'description': 'The California Office of the Attorney General reported a data '
'breach involving Operating Engineers Local Union No. 3 on '
'February 15, 2017. The breach occurred on February 9, 2017, '
'potentially affecting user names, passwords, and email '
'addresses of union website users, with no evidence of '
'unauthorized acquisition of personal data.',
'impact': {'data_compromised': ['user names', 'passwords', 'email addresses'],
'identity_theft_risk': 'No evidence of unauthorized acquisition of '
'personal data'},
'references': [{'source': 'California Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'Reported to the '
'California Office of '
'the Attorney General'},
'title': 'Data Breach at Operating Engineers Local Union No. 3',
'type': 'Data Breach'}