CSIDB logo
Incident

San Francisco Employees Retirement System

Incident posture

Attack window
Feb 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
San Francisco Employees Retirement System
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The San Francisco Employees Retirement System experienced a data breach when an unauthorized party accessed a vendor-hosted test database containing member information. Exposed data included names, addresses, dates of birth, beneficiary details, and—for retirees—IRS Form 1099R data with routing numbers, while registered users also had login credentials and security answers compromised. Though no Social Security numbers or full bank accounts were exposed, the leaked information posed risks for phishing and identity theft. The affected database contained records current up to mid-2018. The organization offered credit monitoring services to impacted individuals following the incident.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

3 techniques

Description

The San Francisco Employees’ Retirement System (SFERS) experienced a data breach involving unauthorized access to a vendor-managed test environment database containing member information. On February 24, 2020, an outside party accessed a server hosted by vendor 10up Inc., which stored data for approximately 74,000 SFERS members. The vendor discovered the intrusion on March 21, 2020, shut down the compromised server, and initiated an investigation. SFERS was notified of the breach on March 26, 2020, after which both organizations collaborated on the investigation. Forensic analysis found no evidence that member data was exfiltrated but could not confirm whether unauthorized viewing or copying occurred. The exposed database contained information from no later than August 29, 2018, as it was part of an outdated test environment.

Compromised data varied based on member status and site interactions. All affected individuals had names, addresses, dates of birth, and beneficiary details exposed. Retired members additionally had IRS Form 1099R information (excluding Social Security Numbers) and bank routing numbers for direct deposits compromised. Members who had registered on SFERS’ website also lost login credentials and security question answers. No Social Security Numbers or full bank account details were stored in the breached database. SFERS offered impacted members a complimentary one-year subscription to Experian’s IdentityWorks credit monitoring service and advised vigilance against phishing attempts leveraging exposed security questions. The organization emphasized direct verification of any suspicious communications purporting to originate from SFERS.

Sources

Sources available to members: 1 source.

CSIDB