Search Data Security Breaches

California law requires a business or state or local agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person. (You can read the law here: California Civil Code s. 1798.29(a) for state agencies and California Civ. Code s. 1798.82(a) for businesses).

The law also requires that a sample copy of a breach notice sent to more than 500 California residents must be provided to the California Attorney General. Below is a list of those sample breach notices. (Note that in some cases the organization that sent the notice is not the one that experienced the breach. For example, a bank may notify of a credit card number breach that occurred not at the bank, but at a merchant.)

You can search by the name of the organization that sent the notice, or simply scroll through the list. To read a notice, click on the name of the organization in the list. Then click on the link titled "Sample Notification."

Download Full Data Breach List (CSV)

Organization Name Date(s) of Breach Reported Date
TABB Inc. (“TABB”) 08/14/2024 02/12/2026
Abbott Laboratories Employees Credit Union (“ALEC”) 08/02/2024 10/18/2024
Abbott 02/21/2024 05/29/2024
AbbVie Inc. 02/21/2024 05/21/2024
Abbott Laboratories 01/19/2019 02/05/2019
Tech Rabbit LLC 02/22/2017, 05/22/2018 09/19/2018
TaskRabbit, Inc. 04/11/2018 05/14/2018
ABB, Inc. 08/25/2017 09/11/2017
Abbott Nutrition n/a 02/24/2017
Abbott Laboratories 12/01/2014 04/17/2015