Search Data Security Breaches

California law requires a business or state or local agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person. (You can read the law here: California Civil Code s. 1798.29(a) for state agencies and California Civ. Code s. 1798.82(a) for businesses).

The law also requires that a sample copy of a breach notice sent to more than 500 California residents must be provided to the California Attorney General. Below is a list of those sample breach notices. (Note that in some cases the organization that sent the notice is not the one that experienced the breach. For example, a bank may notify of a credit card number breach that occurred not at the bank, but at a merchant.)

You can search by the name of the organization that sent the notice, or simply scroll through the list. To read a notice, click on the name of the organization in the list. Then click on the link titled "Sample Notification."

Download Full Data Breach List (CSV)

Organization Name Date(s) of Breach Reported Date
Lokai Holdings LLC 06/27/2014 12/24/2014
Corday Productions, Inc. n/a 12/24/2014
Public Architecture n/a 12/23/2014
Rob Kirby, CPA 12/19/2014 12/23/2014
DutchWear 11/07/2014 12/23/2014
Nvidia Corporation 10/08/2014 12/22/2014
Quest Diagnostics 11/17/2014 12/19/2014
Mercy Medical Center Redding Oncology Clinic 06/01/2014 12/19/2014
Staples, Inc. 08/10/2014 12/19/2014
American Express Travel Related Services Company, Inc and /or its Affiliates (“AXP”) n/a 12/19/2014
American Express Travel Related Services Company, Inc and /or its Affiliates (“AXP”) 07/11/2011 12/19/2014
IDParts, LLC n/a 12/19/2014
Harmonic Inc. 10/17/2014 12/18/2014
Point Loma Nazarene University 10/07/2014, 10/20/2014 12/15/2014
University of California, Berkeley 09/16/2014 12/12/2014
Acosta, Inc. and its subsidiaries, including Mosaic Sales Solutions US Operating Co. LLC 11/10/2014 12/12/2014
ABM Parking Services 09/29/2014, 11/18/2014 12/12/2014
Sony Pictures Entertainment Inc. ("SPE) 11/24/2014 12/11/2014
EMCOR Services Mesa Energy Systems 11/25/2014, 11/24/2014 12/11/2014
bebe stores, inc. 11/08/2014 12/05/2014
American Residuals and Talen, Inc. ("ART") 10/18/2014 12/01/2014
Shutterfly, Inc. n/a 11/26/2014
Godiva Chocolatier, Inc. 10/16/2014 11/25/2014
State Compensation Insurance Fund n/a 11/25/2014
REEVE-WOODS EYE CENTER n/a 11/14/2014
American Express Travel Related Services Company, Inc and /or its Affiliates (“AXP”) n/a 11/07/2014
Palm Springs Federal Credit Union 10/20/2014 11/03/2014
US Investigations Services, LLC n/a 10/29/2014
East West Bank-CA Impacted Customers-Kmart Data Breach 09/01/2014, 10/09/2014 10/27/2014
Fidelity National Financial, Inc. 04/14/2014, 04/16/2014 10/24/2014
American Soccer Company, Inc. 09/04/2014 10/23/2014
Reeves International, Inc. 03/31/2013 10/23/2014
Sourcebooks, Inc. 04/16/2014 10/17/2014
Cyberswim, Inc. 05/12/2014 10/14/2014
University of California Davis Medical Center 09/25/2014 10/13/2014
SAUSALITO YACHT CLUB 09/30/2014 10/10/2014
International Dairy Queen, Inc. (“IDQ”) on behalf of 9 Dairy Queen franchise locations in California listed in the attached addendum. n/a 10/09/2014
Evolution Nature Corp. d/b/a The Evolution Store (Evolution") n/a 10/09/2014
Touchstone Medical Imaging, LLC 05/09/2014 10/03/2014
East West Bank 06/22/2014, 09/17/2014 10/02/2014
Community Technology Alliance 07/28/2014 10/02/2014
East West Bank 04/11/2014, 09/07/2014 10/02/2014
American Express Travel Related Services Company, Inc and /or its Affiliates (“AXP”) 06/13/2013 10/01/2014
Flinn Scientific, Inc. 05/02/2014, 09/08/2014 10/01/2014
Albertson's LLC n/a 09/29/2014
Bay Area Bioscience Association n/a 09/26/2014
Pacific Biosciences of California, Inc. 09/16/2014 09/25/2014
Jimmy John's Franchises LLC 06/16/2014 09/24/2014
American Express Travel Related Services Company, Inc and /or its Affiliates (“AXP”) n/a 09/24/2014
Viator n/a 09/22/2014