Supply chain
⛓ Supply Chain
San Francisco Employees' Retirement System (SFERS) Third-Party Breach (June 2020)
Primary Source ↗Incident Details
San Francisco benefits program breach exposes PII on 74,000. A breach of the San Francisco Employees’ Retirement System (SFERS) may have exposed the information of 74,000 members, including names, addresses, birth dates, banking and IRS data as well as details on beneficiaries. An unauthorized third party on February 24 accessed a database that a SFERS vendor, 10up Inc., was using in a test environment,. “The vendor promptly shut down the server and began an investigation,” the notification said. “The vendor found no evidence that the information of SFERS members was removed from its server, but at this time, it cannot confirm that the information was not viewed or copied by an unauthorized party.”. Third-party company: 10up Inc.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- 10up Inc
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2020-06-01 Breach occurred
- 2020-06-04 Publicly disclosed