Cyber Incident Victim: County of Tehama
Date:
Nov 2021
Location:
United States of America
Summary
The County of Tehama experienced unauthorized access to its Department of Social Services systems over several months, compromising personal information of current and former employees, service recipients, and affiliated individuals. Exposed data included names, dates of birth, mailing addresses, Social Security numbers, driver’s license details, and service-related information. The organization detected suspicious activity, secured its systems, launched an investigation with law enforcement involvement, and later notified potentially affected individuals by mail. Complimentary credit monitoring and identity theft protection were offered to those with exposed sensitive identifiers, alongside a dedicated response line for inquiries. No fraud incidents were reported at the time of disclosure, though enhanced monitoring tools were implemented to prevent future breaches.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The County of Tehama, California, detected suspicious activity on its IT systems on April 9, 2022, prompting immediate protective measures to secure its network. An investigation was launched with law enforcement notification, revealing unauthorized access to the county’s IT infrastructure between November 18, 2021, and April 9, 2022. The breach specifically targeted files within the Department of Social Services’ systems. By August 19, 2022, the investigation concluded that personal information of current and former employees, service recipients, and affiliated individuals was compromised. Exposed data included names, dates of birth, mailing addresses, Social Security numbers, driver’s license numbers, and details related to social services received.

On November 17, 2022, the county initiated notification letters to potentially affected individuals and offered complimentary credit monitoring and identity theft protection for those with exposed Social Security or driver’s license numbers. A dedicated toll-free response line (855-926-1376) was established for inquiries, operational weekdays from 6:00 a.m. to 3:30 p.m. Pacific Time. No fraud incidents linked to the breach had been reported as of the announcement date. The county advised vigilance in monitoring financial accounts for suspicious activity. To mitigate future risks, enhanced monitoring and alerting software were implemented across its systems. The incident did not disrupt ongoing county operations or service delivery during the response period.
