Supply chain ⛓ Supply Chain

San Francisco Employees' Retirement System (SFERS) Third-Party Breach (June 2020)

📅 2020-06-01 🏢 10up Inc
Primary Source ↗

Incident Details

San Francisco benefits program breach exposes PII on 74,000. A breach of the San Francisco Employees’ Retirement System (SFERS) may have exposed the information of 74,000 members, including names, addresses, birth dates, banking and IRS data as well as details on beneficiaries. An unauthorized third party on February 24 accessed a database that a SFERS vendor, 10up Inc., was using in a test environment,. “The vendor promptly shut down the server and began an investigation,” the notification said. “The vendor found no evidence that the information of SFERS members was removed from its server, but at this time, it cannot confirm that the information was not viewed or copied by an unauthorized party.”. Third-party company: 10up Inc.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
10up Inc
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-06-01 Breach occurred
  2. 2020-06-04 Publicly disclosed