Search Data Security Breaches

California law requires a business or state or local agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person. (You can read the law here: California Civil Code s. 1798.29(a) for state agencies and California Civ. Code s. 1798.82(a) for businesses).

The law also requires that a sample copy of a breach notice sent to more than 500 California residents must be provided to the California Attorney General. Below is a list of those sample breach notices. (Note that in some cases the organization that sent the notice is not the one that experienced the breach. For example, a bank may notify of a credit card number breach that occurred not at the bank, but at a merchant.)

You can search by the name of the organization that sent the notice, or simply scroll through the list. To read a notice, click on the name of the organization in the list. Then click on the link titled "Sample Notification."

Download Full Data Breach List (CSV)

Organization Name Date(s) of Breach Reported Date
RCI Internet Services 03/23/2026 05/29/2026
United Food & Commercial Workers Local No. 7 12/10/2024 11/24/2025
CF Arcis XII, LLC dba Arcis Golf 11/16/2023 07/01/2024
Plavan Commercial Fueling Inc. ("P-Fleet") 02/23/2024 06/24/2024
SinglePoint Outsourcing, Inc. 11/08/2023 04/12/2024
SinglePoint Outsourcing, Inc. 11/08/2023 03/26/2024
Fiduciary Outsourcing, LLC 05/31/2023 03/19/2024
RCI, LLC (“RCI”) 05/31/2023, 06/01/2023 03/01/2024
SinglePoint Outsourcing, Inc. 11/08/2023 02/08/2024
Frax Outsourcing, a subsidiary of TheKey, LLC 11/02/2022 10/10/2023
Young’s Commercial Transfer 01/20/2023, 01/21/2023 05/17/2023
Convergent Outsourcing, Inc. 06/17/2022 11/01/2022
Tiburcio Vasquez Health Center Inc. 02/06/2021 06/22/2021