Search Data Security Breaches

California law requires a business or state or local agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person. (You can read the law here: California Civil Code s. 1798.29(a) for state agencies and California Civ. Code s. 1798.82(a) for businesses).

The law also requires that a sample copy of a breach notice sent to more than 500 California residents must be provided to the California Attorney General. Below is a list of those sample breach notices. (Note that in some cases the organization that sent the notice is not the one that experienced the breach. For example, a bank may notify of a credit card number breach that occurred not at the bank, but at a merchant.)

You can search by the name of the organization that sent the notice, or simply scroll through the list. To read a notice, click on the name of the organization in the list. Then click on the link titled "Sample Notification."

Download Full Data Breach List (CSV)

Organization Name Date(s) of Breach Reported Date
Smith & James, CPAs 03/05/2026 05/28/2026
DOUGLAS M SMITH & CO CPAS 01/20/2026 04/15/2026
DH Smith Company, Inc 03/27/2025 01/27/2026
Comyns, Smith, McCleary & Deaver LLP 09/30/2024 06/10/2025
GlaxoSmithKline Group of Companies and the GlaxoSmithKline Patient Access Programs Foundation 02/21/2024 05/24/2024
Smithfield Specialty Foods Group LLC ("Smithfield" or the "Company") 11/24/2021, 12/14/2022 06/29/2023
Smith, Gambrell & Russell, LLP 08/09/2021 03/01/2023
Kaye-Smith Enterprises, Inc. 05/18/2022, 06/02/2022 08/29/2022
Smith, Gambrell & Russell, LLP 08/09/2021 08/08/2022
Lozano Smith 01/01/2020 12/14/2021
Smith and Company 03/23/2021 04/22/2021
Ascentium Corporation dba SMITH 12/24/2020 04/13/2021
Ascentium inc. and Ascentium Corp. (Smith) 12/24/2020, 02/24/2021 03/23/2021
Douglas M. Smith & Co. CPA 03/25/2020 07/07/2020