The finding
Disclosure specificity is rising, year over year
A notification letter is not required to say how the attacker got in, and most do not. But the share that does has risen in every year of this corpus. Each row below is the letters filed in that calendar year whose narrative section could be read, and how many of them named a vector.
| Report year | Letters read | Named a vector | Rate | Rate, drawn to scale |
|---|---|---|---|---|
| 2023 | 582 | 9 | 1.5% | |
| 2024 | 549 | 13 | 2.4% | |
| 2025 | 505 | 18 | 3.6% | |
| 2026through Aug 14, 2026 | 298 | 20 | 6.7% |
The 2026 row covers filings reported through 14 August 2026 and is therefore a partial year. It is shown as its own window rather than annualized, because the underlying rate is still moving.
What the named vectors are
Across the full corpus, 53 distinct incidents name a vector. Their distribution is below. Two caveats that matter: this is the distribution of the named subset, not of all breaches, and the ordering shifts by window — in 2026 filings alone, deception of a person runs far closer to credential theft than the corpus totals suggest.
| Vector named in the letter | Distinct incidents | Share of named | Share, drawn to scale |
|---|---|---|---|
| Phished or stolen credentialsA valid username and password reached the attacker — phished, reused, purchased, or taken from an earlier breach. | 31 | 58.5% | |
| Social engineering of a personA human was deceived into granting access, resetting a credential, or approving a request. Includes vishing and help-desk pretexting. | 12 | 22.6% | |
| Third-party or contractor accessThe path in belonged to a vendor, contractor, or service provider rather than to the filing organization. | 9 | 17% | |
| MFA bypassA second factor was defeated rather than absent — push fatigue, prompt bombing, or a bypassed enrollment flow. | 1 | 1.9% | |
| Total distinct incidents naming a vector | 53 | 100% |
The negative result
Five identity vectors appear zero times in 2,161 filings
The classification filter looked for nine identity vectors. Four are observable in California notification letters. These five are not — not rarely, not once:
Session or token theft
Cookie replay and stolen session tokens.
Orphaned or dormant accounts
Accounts that outlived the person or the purpose.
Over-provisioned standing access
Privilege creep and entitlements nobody revoked.
Service-account or non-human identity abuse
Machine credentials used as a way in.
SSO, IdP, or federation compromise
The identity provider itself as the target.
At a sample of 98 letters this looked like sparsity. At 2,161 it is a finding about disclosure practice, not about attacker behaviour. Session theft, dormant accounts, standing privilege, machine identities, and federation compromise are well documented in incident-response reporting. They do not survive the trip into a consumer notification letter. Anyone sizing these risks from public disclosure alone will size them at zero.
The evidence
The cited incidents
Every incident below carries the sentence from its own notification letter that establishes the vector, quoted verbatim, plus a link to that letter as filed with the California Attorney General. No incident is classified by inference. If a letter does not say it, it is not here.
Grouped by the vector the letter names. Each group opens to every incident in it, with its quote, its dates, and links to the letter and the filing.
Phished or stolen credentials31 incidentsA valid username and password reached the attacker — phished, reused, purchased, or taken from an earlier breach.
Xsolis, Inc.
Sector: Not classified
“Xsolis became aware of unauthorized activity resulting from a targeted phishing attack on January 22, 2026.”
- Breach began
- Jan 20, 2026
- Detected
- Jan 22, 2026
- Filed
- Jul 21, 2026
First Advantage Corporation
Sector: Not classified
“On November 17, 2025, First Advantage became aware that an unauthorized third party obtained access through sophisticated phishing to a single First Advantage Drug & Occupational Health Screening Unit employee’s account.”
- Breach began
- Nov 13, 2025
- Detected
- Nov 17, 2025
- Filed
- Jun 23, 2026
Nickey Kehoe
Sector: Not classified
“Within 24 hours of the event, we had removed the compromised access credentials, and improved the security protocols and processes associated with accessing the system.”
- Breach began
- Mar 29, 2026
- Detected
- Mar 29, 2026
- Filed
- May 26, 2026
Whitepages
Sector: Not classified
“We determined that these attempts were part of a “credential stuffing” attack, in which someone used lists of usernames and passwords stolen from other, unrelated websites to try to log in to accounts on our site.”
- Breach began
- Mar 24, 2026
- Detected
- Mar 24, 2026
- Filed
- Mar 31, 2026
Insurance Office of America ("IOA")
Sector: Insurance
“Based on this investigation, we determined that an unauthorized party gained access to our network as a result of a phishing email attack.”
- Breach began
- Jun 25, 2025
- Detected
- Jun 30, 2025
- Filed
- Jan 16, 2026
Outcomes One, Inc.
Sector: Not classified
“We recently completed an investigation related to an email phishing incident that occurred on July 1, 2025.”
- Breach began
- Jul 1, 2025
- Detected
- Not stated
- Filed
- Oct 23, 2025
Superior Vision Services, Inc.
Sector: Not classified
“On July 9, 2025, a Superior Vision employee was the victim of a sophisticated phishing attack.”
- Breach began
- Jul 9, 2025
- Detected
- Not stated
- Filed
- Sep 29, 2025
Whitepages
Sector: Not classified
“We determined that these attempts were part of a “credential stuffing” attack, in which someone used lists of usernames and passwords stolen from other, unrelated websites to try to log in to accounts on our site.”
- Breach began
- Jul 19, 2025
- Detected
- Jul 19, 2025
- Filed
- Aug 22, 2025
Genex Services, LLC
Sector: Not classified
“Our investigation determined that Genex was the victim of a phishing attack that compromised the laptops of two employees.”
- Breach began
- Jan 22, 2025
- Detected
- Feb 25, 2025
- Filed
- Jul 9, 2025
Humboldt Independent Practice Association
Sector: Nonprofit
“On June 28, 2024, Humboldt IPA became aware of a phishing campaign, designed to appear as a legitimate communication from one of our partners.”
- Breach began
- Jun 27, 2024
- Detected
- Jun 28, 2024
- Filed
- May 23, 2025
Culinary Services of America Inc.
Sector: Not classified
“On or around March 3, 2025, CSA became aware that a phishing email had been sent to one of its employees.”
- Breach began
- Mar 3, 2025
- Detected
- Not stated
- Filed
- May 8, 2025
SogoTrade, Inc.
Sector: Not classified
“(“SogoTrade”) learned that a phishing email containing malicious software led to the compromise of four email accounts by an unauthorized party that may have resulted in the exposure of affected individuals’ personal information.”
- Breach began
- May 8, 2024
- Detected
- Not stated
- Filed
- May 7, 2025
SAG-AFTRA Health Plan
Sector: Healthcare
“This incident resulted from a phishing email, and it is important to note that the Plan’s systems were not impacted.”
- Breach began
- Sep 17, 2024
- Detected
- Sep 18, 2024
- Filed
- Mar 14, 2025
Avery Products Corporation
Sector: Manufacturing
“We do not know if fraudulent charges are related to our website incident, but it now appears possible that payment-card (and other) information may have been acquired as we received two emails from customers who indicated that they incurred a fraudulent charge and/or phishing email.”
- Breach began
- Jul 19, 2024
- Detected
- Dec 9, 2024
- Filed
- Feb 11, 2025
Avery Products Corporation
Sector: Manufacturing
“We do not know if fraudulent charges are related to our website incident, but it now appears possible that payment-card (and other) information may have been acquired as we received two emails from customers who indicated that they incurred a fraudulent charge and/or phishing email.”
- Breach began
- Jul 18, 2024
- Detected
- Dec 9, 2024
- Filed
- Jan 16, 2025
Phase II Systems d/b/a PARS
Sector: Technology
“As a result of a phishing incident, an unauthorized party obtained access to a PARS employee’s email account.”
- Breach began
- Mar 11, 2024
- Detected
- Not stated
- Filed
- Aug 29, 2024
United of Omaha Life Insurance Company
Sector: Insurance
“The access was the result of a phishing campaign targeting United of Omaha employees.”
- Breach began
- Apr 21, 2024
- Detected
- Apr 23, 2024
- Filed
- Jul 26, 2024
Allcare Medical Management, Inc.
Sector: Healthcare
“Based on the investigation, the likely purpose of the unauthorized access to the email account was to perpetuate an email phishing scheme, not to access personal information.”
- Breach began
- Mar 4, 2024
- Detected
- Not stated
- Filed
- Jul 22, 2024
Levi Strauss & Co.
Sector: Not classified
“Our investigation showed characteristics associated with a “credential stuffing” attack where bad actor(s) who have obtained compromised account credentials from another source (such as a third-party data breach) then use a bot attack to test these credentials against another website – in this case www.”
- Breach began
- Jun 13, 2024
- Detected
- Not stated
- Filed
- Jun 21, 2024
Los Angeles County Dept of Public Health
Sector: Healthcare
“Between February 19, 2024, and February 20, 2024, DPH experienced a phishing attack.”
- Breach began
- Feb 19, 2024
- Detected
- Not stated
- Filed
- Jun 14, 2024
Los Angeles County - Department of Health Services
Sector: Healthcare
“Between February 19, 2024, and February 20, 2024, DHS experienced a phishing attack.”
- Breach began
- Feb 19, 2024
- Detected
- Not stated
- Filed
- Apr 25, 2024
California Statewide Automated Welfare System
Sector: Technology
“On February 9, 2024, BenefitsCal discovered that someone, that was not allowed, may have logged into accounts of some users of the BenefitsCal website using reused passwords taken from other websites.”
- Breach began
- Mar 1, 2023
- Detected
- Feb 9, 2024
- Filed
- Apr 5, 2024
UC San Diego Health Hillcrest - Hillcrest Medical Center
Sector: Healthcare
“On January 9, 2024, we identified a phishing attack against UC San Diego Health employees, which resulted in unauthorized access to two employee email accounts.”
- Breach began
- Jan 9, 2024
- Detected
- Jan 9, 2024
- Filed
- Mar 8, 2024
23andMe, Inc.
Sector: Not classified
“Based on our investigation, we believe a threat actor orchestrated a credential stuffing attack during the period from May 2023 through September 2023 to gain access to one or more 23andMe accounts that are connected to you through our optional DNA Relatives feature.”
- Breach began
- Apr 29, 2023
- Detected
- Not stated
- Filed
- Jan 21, 2024
ZOLL Medical Corporation
Sector: Healthcare
“Threat actors use different strategies to attack companies to obtain access to data, including phishing email campaigns.”
- Breach began
- Aug 2, 2023
- Detected
- Not stated
- Filed
- Dec 18, 2023
CRC Insurance Services, LLC
Sector: Insurance
“On or about January 18, 2023, CRC Insurance Services, LLC (“CRC”) determined that through a series of phishing emails, an unknown third-party gained unauthorized access for a limited period of time to a small number of employee email accounts and exfiltrated a small percentage of emails in those accounts.”
- Breach began
- Jan 13, 2023
- Detected
- Not stated
- Filed
- Dec 8, 2023
Heavy Hammer
Sector: Not classified
“At the present time, we believe this ransomware attack occurred after several of our employees were victims of a phishing attack.”
- Breach began
- Apr 21, 2023
- Detected
- Not stated
- Filed
- Jun 6, 2023
County of Contra Costa, California
Sector: Government
“The County of Contra Costa recently concluded its investigation of and data analysis for an email phishing incident that may have resulted in unauthorized access to emails and attachments in two email accounts.”
- Breach began
- Sep 19, 2022
- Detected
- Not stated
- Filed
- May 11, 2023
Svanaco, Inc. dba Americaneagle.com
Sector: Not classified
“com learned an unauthorized actor leveraged an AmericanEagle employee’s compromised credentials to access and install malicious code on the https://www.”
- Breach began
- Jul 25, 2022
- Detected
- Not stated
- Filed
- Mar 29, 2023
EPIC MANAGEMENT LLC
Sector: Not classified
“We discovered that an unauthorized third-party launched a targeted phishing attack and temporarily gained access to certain emails and records on the employee’s account.”
- Breach began
- Jan 24, 2023
- Detected
- Jan 24, 2023
- Filed
- Mar 8, 2023
Saltzman & Johnson Law Corporation
Sector: Legal services
“On March 7, 2022, SJLC received notice that a phishing campaign originated from one of our employee’s email account.”
- Breach began
- Mar 7, 2022
- Detected
- Not stated
- Filed
- Mar 3, 2023
12 incidentsA human was deceived into granting access, resetting a credential, or approving a request. Includes vishing and help-desk pretexting.
Quantum Health, Inc.
Sector: Healthcare
“Our investigation determined that the service outage was related to unauthorized access to our IT network, resulting from a user responding to a vishing call on May 29, 2026.”
- Breach began
- May 29, 2026
- Detected
- Jun 1, 2026
- Filed
- Aug 14, 2026
Lennar Mortgage, LLC
Sector: Financial services
“We then determined that an unauthorized party used sophisticated social engineering tactics to access some of our systems between May 26, 2026 and June 1, 2026.”
- Breach began
- May 26, 2026
- Detected
- Jun 1, 2026
- Filed
- Aug 14, 2026
AdaptHealth, LLC
Sector: Healthcare
“Through this investigation, we learned that the unauthorized third-party gained access to our systems on June 5 through a social engineering attack targeting a single company user account and took with them certain data, including patient information.”
- Breach began
- Jun 5, 2026
- Detected
- Jun 15, 2026
- Filed
- Aug 14, 2026
Lennar Corporation
Sector: Not classified
“We then determined that an unauthorized party used sophisticated social engineering tactics to access some of our systems between March 24, 2026, and March 30, 2026.”
- Breach began
- Mar 24, 2026
- Detected
- Mar 30, 2026
- Filed
- Aug 11, 2026
Fox Rothschild LLP
Sector: Legal services
“Our investigation determined that on May 21, 2026 the employee was the target of a social engineering attack, commonly referred to as “vishing”, and certain files were copied and taken.”
- Breach began
- May 21, 2026
- Detected
- May 21, 2026
- Filed
- Jul 16, 2026
Markel Insurance
Sector: Insurance
“We recently identified that an unauthorized actor used social engineering to deceive two employees to gain access to a limited portion of Markel’s systems between March 17-18, 2026.”
- Breach began
- Mar 17, 2026
- Detected
- Not stated
- Filed
- Jul 2, 2026
Eisen, Inc.
Sector: Not classified
“was targeted by a sophisticated social engineering attack.”
- Breach began
- Dec 12, 2025
- Detected
- Not stated
- Filed
- Jun 24, 2026
Horizon Media
Sector: Media
“On January 9, 2026, Horizon learned that an unauthorized actor gained access to a limited portion of our systems through a sophisticated social engineering event.”
- Breach began
- Jan 9, 2026
- Detected
- Jan 9, 2026
- Filed
- May 6, 2026
CHP 11-99 Foundation
Sector: Nonprofit
“Being vigilant about security, the staff member forwarded the email to the Foundation’s external service provider’s Help Desk for inspection and guidance.”
- Breach began
- Sep 16, 2025
- Detected
- Sep 24, 2025
- Filed
- Apr 1, 2026
Insight Partners
Sector: Not classified
“Insight Partners’ investigation into the incident determined that, on or around October 25, 2024, a threat actor successfully used a sophisticated social engineering attack to gain access to the affected servers.”
- Breach began
- Oct 25, 2024
- Detected
- Jan 16, 2025
- Filed
- Sep 15, 2025
Coinbase, Inc.
Sector: Not classified
“, transaction history, balance, transfers, date you opened your account) Attackers seek out this information because they want to conduct social engineering attacks, using this information to appear credible to try and convince victims to move their funds.”
- Breach began
- Dec 26, 2024
- Detected
- Not stated
- Filed
- May 20, 2025
GPD Holdings LLC d/b/a CoinFlip
Sector: Not classified
“On August 7, 2023, an unauthorized third-party utilized sophisticated social engineering tactics to access certain CoinFlip systems by compromising a CoinFlip employee’s account.”
- Breach began
- Aug 7, 2023
- Detected
- Not stated
- Filed
- Oct 23, 2023
Third-party or contractor access9 incidentsThe path in belonged to a vendor, contractor, or service provider rather than to the filing organization.
LifeLong Medical Care
Sector: Healthcare
“On October 2, 2025, TriZetto Provider Solutions (“TPS”) a Business Associate of our organization, became aware of suspicious activity within a web portal that some of TPS’s healthcare provider customers use to access our systems.”
- Breach began
- Nov 1, 2024
- Detected
- Oct 2, 2025
- Filed
- Jan 14, 2026
County of Santa Barbara Health Department
Sector: Healthcare
“The incident occurred at OCHIN’s business associate TriZetto Provider Solutions, a branch of Cognizant Technology Solutions Corporation.”
- Breach began
- Nov 1, 2024
- Detected
- Not stated
- Filed
- Jan 12, 2026
Asian and Pacific Islander Wellness Center, Inc. dba San Francisco Community Health Center
Sector: Healthcare
“On December 12, 2025, San Francisco Community Health Center (SFCHC) was notified by OCHIN, its business associate that supports SFCHC’s Epic electronic health record system, of a data security incident involving one of OCHIN’s subcontractors, TriZetto Provider Solutions (TriZetto), a healthcare eligibility and claims clearinghouse.”
- Breach began
- Nov 1, 2024
- Detected
- Oct 2, 2025
- Filed
- Jan 9, 2026
Mission Neighborhood Health Center
Sector: Healthcare
“On December 12, 2025, Mission Neighborhood Health Center (MNHC) was notified by OCHIN, its business associate that supports MNHC’s Epic electronic health record system, of a data security incident involving one of OCHIN’s subcontractors, TriZetto, a healthcare eligibility and claims clearinghouse.”
- Breach began
- Nov 1, 2024
- Detected
- Oct 2, 2025
- Filed
- Jan 7, 2026
Planned Parenthood Northern California
Sector: Not classified
“On December 10, 2025, our business associate, OCHIN notified us of a cyber security incident involving one of their subcontractors, Trizetto Provider Solutions (“TPS”).”
- Breach began
- Not stated
- Detected
- Not stated
- Filed
- Dec 30, 2025
Adamson Ahdoot LLP
Sector: Legal services
“000010102G0500 December 19, 2025 What Happened? In November 2025, we learned that a third-party vendor with authorized access to certain cloud-hosted firm resources may have unintentionally permitted, directly or indirectly, unauthorized access to cloud-hosted firm documents.”
- Breach began
- Oct 27, 2025
- Detected
- Not stated
- Filed
- Dec 19, 2025
Benworth Capital Partners
Sector: Financial services
“We believe that the incident occurred when a criminal actor accessed certain components of our systems through a third-party service provider.”
- Breach began
- May 16, 2025
- Detected
- May 23, 2025
- Filed
- Oct 31, 2025
Farmers New World Life Insurance Company
Sector: Insurance
“On May 30, 2025, FNWL’s parent company was alerted that a third-party vendor identified suspicious activity involving an unauthorized actor accessing one of the vendor’s databases containing FNWL customer information (the “Incident”).”
- Breach began
- May 29, 2025
- Detected
- May 30, 2025
- Filed
- Aug 22, 2025
CUSO Financial Services, LP
Sector: Financial services
“On January 19, 2024, CUSO became aware of suspicious activity involving a third-party service provider which we use for archiving communications as required by The Financial Industry Regulatory Authority (“FINRA”).”
- Breach began
- Dec 19, 2023
- Detected
- Jan 19, 2024
- Filed
- Oct 28, 2024
MFA bypass1 incidentA second factor was defeated rather than absent — push fatigue, prompt bombing, or a bypassed enrollment flow.
Bankers Life and Casualty Company
Sector: Insurance
“Based on our investigation and response to this event, however, it appears the threat actor was able to bypass the multi-factor authentication and other common security controls the company had in place that were designed to protect the company’s data.”
- Breach began
- Nov 28, 2023
- Detected
- Nov 29, 2023
- Filed
- Jan 29, 2024
The dense layer
The dense layer: how long before anyone was told
Vector is stated in about one filing in thirty. Dates are stated in almost all of them. That makes disclosure lag — the days between when a breach began and when the organization filed its notification — the one axis this corpus can carry at full weight: 2,030 of 2,161 filings.
157days
Median, breach start to filing
n = 2,030 filings
83days
25th percentile — the faster quarter
a quarter filed sooner than this
277days
75th percentile
a quarter took longer than this
414days
90th percentile
one in ten took longer
What 157 days is not
It is not time spent undetected, and it has nothing to do with zero-day exposure. The clock starts on the day the breach began and stops on the day the notification was filed, so it contains the undetected period, the investigation, the legal review, and the notification process itself — most of it after the organization already knew. Where a letter states both the first and last day of access, the attacker's own window runs to a median of 7 days. The two numbers answer different questions and neither substitutes for the other.
- Middle half (25th–75th percentile)
- Median
- 90th percentile
By quarter filed
Lag rose through 2024 and has held near six months since. The most recent two quarters are lower, but recent quarters are structurally biased downward — a breach with a long lag has not been filed yet, so it cannot appear.
| Quarter filed | Filings | Median | Middle half | 90th pct | Distribution |
|---|---|---|---|---|---|
| Q1 2023 | 109 | 118 | 50–280 | 419 | |
| Q2 2023 | 131 | 110 | 63–200 | 403 | |
| Q3 2023 | 206 | 97 | 64–175 | 273 | |
| Q4 2023 | 161 | 178 | 112–266 | 383 | |
| Q1 2024 | 164 | 208 | 96–300 | 470 | |
| Q2 2024 | 151 | 155 | 92–262 | 395 | |
| Q3 2024 | 129 | 173 | 100–277 | 386 | |
| Q4 2024 | 133 | 182 | 105–296 | 408 | |
| Q1 2025 | 120 | 183 | 108–357 | 414 | |
| Q2 2025 | 133 | 184 | 100–337 | 437 | |
| Q3 2025 | 141 | 187 | 83–248 | 337 | |
| Q4 2025 | 133 | 187 | 89–313 | 394 | |
| Q1 2026 | 134 | 184 | 91–358 | 441 | |
| Q2 2026 | 117 | 131 | 67–302 | 478 | |
| Q3 2026 | 68 | 132 | 77–244 | 361 |
Days from breach start to filing · axis to 700 days
By sector
Sector is derived from the organization name, because California publishes no sector field. Sectors below the 15-filing floor are listed separately with their counts and no median.
| Sector | Filings | Median | Middle half | 90th pct | Distribution |
|---|---|---|---|---|---|
| Manufacturing | 20 | 205 | 144–487 | 615 | |
| Government | 51 | 205 | 57–331 | 424 | |
| Education | 131 | 203 | 85–325 | 465 | |
| Legal services | 76 | 182 | 107–343 | 518 | |
| Healthcare | 330 | 171 | 87–311 | 434 | |
| Financial services | 212 | 142 | 70–244 | 330 | |
| Nonprofit | 50 | 138 | 83–259 | 330 | |
| Technology | 78 | 137 | 83–289 | 414 | |
| Retail | 28 | 134 | 87–367 | 680 | |
| Insurance | 100 | 123 | 72–223 | 389 | |
| Hospitality | 31 | 122 | 55–180 | 243 | |
| Real estate | 24 | 107 | 45–187 | 253 | |
| Energy & utilities | 15 | 59 | 28–147 | 156 |
Days from breach start to filing · axis to 700 days
Sectors below the reporting floor
These sectors have too few filings for a median to mean anything. Their counts are published; their medians are not.
- Transport & logistics5 filings — Too few filings to report a median
- Agriculture8 filings — Too few filings to report a median
- Media10 filings — Too few filings to report a median
- Staffing & HR9 filings — Too few filings to report a median
How does your sector compare?
Pick a sector to see its disclosure lag against the California-wide median, drawn from the same 2,030 filings as the tables above. Nothing is sent anywhere — the figures are already on this page.
The intrusion window is short. The silence is not.
Where a letter states both the start and the end of the intrusion, the window between them is short. Set that against the disclosure lag above: the attacker's time inside is measured in days, and the time before anyone outside knew is measured in months.
7days
Median intrusion window, start to end
n = 880 filings
2days
25th percentile
a quarter were shorter
25days
75th percentile
a quarter were longer
88days
90th percentile
one in ten were longer
Definition
What this is
The Identity Attack Ledger is a cited incident ledger. It takes every breach notification filed with the California Attorney General since 1 January 2023, measures the disclosure lag from the dates the letter itself states, and — where the letter names how the attacker got in — records that vector with the sentence that establishes it.
It exists because the question upstream of “what would a breach cost me” is “where am I exposed, and how do I compare.” That question is usually answered with vendor survey data. This answers it with primary filings, one link per claim.
Every figure on this page is precomputed from the corpus and shipped as static text. There is no live feed, because the primary source moves in weeks and a live badge over stale data is worse than a dated one.
What this is not
- Not a live attack map. Attacker IP is a residential proxy and victim location is a legal filing address; neither is an axis a security team can act on.
- Not a national picture. California only. Other states publish on different schedules, with different thresholds, and Maine's portal has been offline since 2024.
- Not a ranking of vendors, and not a claim that any of these organizations were negligent. A filing is a disclosure, not a verdict.
- Not a count of breaches. One record is one filing. A single incident can generate several filings, and the vector layer deduplicates to distinct incidents while the lag layer does not.
Methodology
Methodology
Everything below is a limitation a reader should know before quoting a figure from this page. They are published here rather than buried, because the ledger's only real asset is that its numbers survive being checked.
- Unit of analysis
- One record is one filing submitted to the California Attorney General.
- Statistic used
- Median. Disclosure lag is right-skewed, so means overstate the typical case.
- Reporting floor
- Any cell with fewer than 15 filings is published with its count and no median. Too few filings to report a median.
- Sector derivation
- Derived from the organization name; California publishes no sector field. 852 filings could not be classified and are excluded from the industry table.
- Vector rule
- A vector is recorded only where the letter's own narrative states it, quoted verbatim. Advice, remediation, and denial language is excluded.
- Vectors absent from the corpus
- Session theft, orphaned accounts, over-provisioned access, service-account abuse, and SSO compromise appear in zero filings across this corpus.
- Vector precision
- Roughly 90%, hand-checked on 11 of the 53 cited incidents, which found 1 false positive. One known false-positive class remains: the help-desk pattern matches a letter that mentions a help desk without the desk being the attack path.
- No organization size
- California publishes no size or headcount field and the letters do not carry one reliably, so the ledger has no size band. Comparisons here are by sector and by quarter only.
- Unreadable filings
- Of 2,161 filings, 1,934 yielded a readable narrative section. 191 had no recognisable section structure and 35 were scanned images with no text layer. Lag figures still use every filing whose dates are stated, because excluding image-only filings would bias the result toward organizations that happen to file text-layer PDFs.
- Deduplication
- The vector layer collapses multiple filings of the same event into one incident, keyed on breach start date and evidence text. Same-incident filings that state different breach dates are not caught, which would slightly overstate the distinct-incident count. The lag layer does not deduplicate — one record there is one filing.
- Geographic scope
- California only. Do not read any rate on this page as a national rate. Federal SEC filings were measured and rejected as a vector source: securities counsel discloses the fact of unauthorized access and conceals the mechanism. Maine's public portal has been offline indefinitely since 2024.
- Recent-quarter bias
- The most recent quarters under-represent long-lag breaches by construction: a breach that began two years ago and has not yet been filed cannot appear in the data. Read the latest one or two quarters as provisional.
Corpus built from California Attorney General breach notification list. Every figure on this page is precomputed and served as static HTML.
New filings land every quarter
The California Attorney General publishes continuously. This ledger is rebuilt each quarter — one email when the next batch is in, with what changed.
One email per quarter. Nothing else.
FAQ
Questions
What is the Identity Attack Ledger?
It is a public ledger of every data breach notification filed with the California Attorney General since 1 January 2023 — 2,161 filings. Each filing is measured for disclosure lag, the number of days between when the breach began and when the organization filed its notification. Where the notification letter states how the attacker got in, the ledger records that vector along with the verbatim sentence from the letter and a link to the letter itself. It is published free by Avatier, an identity and access management vendor.
How long do organizations take to disclose a breach?
Across 2,030 California filings from 2023 through 14 August 2026 where both dates are stated, the median is 157 days between the start of the breach and the filing of the notification. A quarter of filings took 83 days or fewer; a quarter took more than 277 days; one in ten took more than 414 days. The median is used rather than the mean because the distribution is right-skewed — a handful of very long lags would pull an average well above the typical case.
How often do breach notifications say how the attacker got in?
Rarely, but increasingly. Of the letters filed in 2023 whose narrative could be read, 1.5% named an attack vector. That rose to 2.4% in 2024, 3.6% in 2025, and 6.7% of filings reported between 1 January and 14 August 2026. Because the rate has risen in every year, a single corpus-wide average would understate current disclosure practice and overstate the history, so this page always publishes a rate with its window attached.
Which identity vector shows up most often?
Of the 53 distinct incidents across the corpus whose letters name a vector, 31 name a phished or stolen credential, 12 name social engineering of a person, 9 name third-party or contractor access, and 1 names an MFA bypass. That is the distribution of the named subset only — it is not the distribution of all breaches, and it is not evidence about the vectors letters do not name. The ordering also depends on the window: in the most recent filings, deception of a person runs much closer to credential theft than the corpus totals suggest.
Why do session theft and orphaned accounts show zero incidents?
Because no notification letter in this corpus describes them. The classification filter searched for nine identity vectors across 2,161 filings. Session or token theft, orphaned or dormant accounts, over-provisioned standing access, service-account abuse, and SSO or federation compromise appear zero times. That is a statement about what US breach notification letters disclose, not about how often those attacks happen. All five are well documented in incident-response reporting; none of them survive into a consumer notification.
How is a vector classified, and can I check it?
A vector is recorded only where the letter's own narrative section states it. Matching is scoped to the “What Happened” section, because consumer advice and remediation boilerplate elsewhere in these letters use the same vocabulary without describing the attack — that was the single largest source of false positives in testing. Negations and remediation language are rejected explicitly. Every classification on this page shows its quote and links to the filed PDF, so any entry can be checked at source in about thirty seconds.
How accurate is the classification?
A hand check of 11 of the 53 cited incidents found 1 false positive, putting precision near 90%. One known weakness remains: the help-desk pattern matches letters where a help desk is mentioned without the desk itself being the attack path. Deduplication also misses same-incident filings whose stated breach dates differ, which would slightly overstate the distinct-incident count. Both are disclosed rather than corrected, because correcting them by hand would make the corpus unreproducible.
Why California, and why not a national picture?
California publishes both a searchable filing list and the actual submitted notification letters, which is what makes vector extraction possible at all. Federal SEC filings were measured and rejected: across the same window, “unauthorized access” appears in roughly 6,800 filings while “compromised credentials” appears in 8, because securities counsel discloses the fact and conceals the mechanism. Maine's public portal has been offline indefinitely since 2024. So the ledger is California only, and should not be read as a national rate.
Where does the sector breakdown come from?
From the organization's name, because California publishes no sector field. 852 of the 2,030 lag-computable filings could not be classified this way and are excluded from the sector table entirely rather than bucketed into “other.” Sectors with fewer than 15 filings are shown with their counts and no median, because a median over five filings is noise wearing a statistic's clothes.
Can I reuse these figures?
Yes. Cite the Identity Attack Ledger by Avatier and state the window for any rate you quote, since several of the rates on this page move year over year. Every underlying document is a public California Attorney General filing and is linked from the incident that uses it, so you can verify any single claim without going through us.
You know the lag. Now price the incident.
157 days is the gap between a breach beginning and a regulator hearing about it — detection, forensics, legal review and notification, all of it. The attacker's own window is far shorter: a median of 7 days between the first and last day of access. The AttackCost calculator prices the disruption rather than the silence — outage duration, productivity, revenue, incident response and market value for your own organization, free and without a sign-up.
Published by Avatier. Every figure traceable to a California Attorney General filing.