CSIDB logo
Incident

County of Tehama

Incident posture

Attack window
Nov 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-21 00:00

Linked entities

Victim
County of Tehama
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The County of Tehama experienced unauthorized access to its Department of Social Services systems over several months, compromising personal information of current and former employees, service recipients, and affiliated individuals. Exposed data included names, dates of birth, mailing addresses, Social Security numbers, driver’s license details, and service-related information. The organization detected suspicious activity, secured its systems, launched an investigation with law enforcement involvement, and later notified potentially affected individuals by mail. Complimentary credit monitoring and identity theft protection were offered to those with exposed sensitive identifiers, alongside a dedicated response line for inquiries. No fraud incidents were reported at the time of disclosure, though enhanced monitoring tools were implemented to prevent future breaches.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The County of Tehama, California, detected suspicious activity on its IT systems on April 9, 2022, prompting immediate protective measures to secure its network. An investigation was launched with law enforcement notification, revealing unauthorized access to the county’s IT infrastructure between November 18, 2021, and April 9, 2022. The breach specifically targeted files within the Department of Social Services’ systems. By August 19, 2022, the investigation concluded that personal information of current and former employees, service recipients, and affiliated individuals was compromised. Exposed data included names, dates of birth, mailing addresses, Social Security numbers, driver’s license numbers, and details related to social services received.

On November 17, 2022, the county initiated notification letters to potentially affected individuals and offered complimentary credit monitoring and identity theft protection for those with exposed Social Security or driver’s license numbers. A dedicated toll-free response line (855-926-1376) was established for inquiries, operational weekdays from 6:00 a.m. to 3:30 p.m. Pacific Time. No fraud incidents linked to the breach had been reported as of the announcement date. The county advised vigilance in monitoring financial accounts for suspicious activity. To mitigate future risks, enhanced monitoring and alerting software were implemented across its systems. The incident did not disrupt ongoing county operations or service delivery during the response period.

Sources

Sources available to members: 1 source.

CSIDB