The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Corporation Service Company (CSC) reported that an unknown actor copied a database table containing personal information on November 25, 2017. CSC said it discovered the theft on April 5, 2018; its May 17 filing with California’s attorney general identified approximately 5,678 California residents as potentially affected. The notice described names paired with Social Security numbers or payment-card information, not necessarily every data type for every person.
What happened in the CSC breach?
CSC provides corporate services, including acting as an agent for service of process. In its California filing, the company said it detected unauthorized access to its network and systems through routine monitoring. It later determined that an unknown actor had exfiltrated a database table on November 25, 2017. CSC said it made that determination on April 5, 2018, and submitted its notice to the California attorney general on May 17, 2018. CyberScoop’s May 21, 2018 report covered the incident.
The filing does not explain how the actor gained access. CyberScoop also noted that the access method had not been specified, so the available accounts do not establish a particular vulnerability or attack technique.
What information may have been affected?
CSC said the data came from information provided by its clients. The notice described combinations of names and Social Security numbers or credit/debit card information. CyberScoop likewise reported names, Social Security numbers, and payment-card information among the data potentially at risk. The wording does not establish that each potentially affected person had every listed type of information in the table, or that anyone’s information was misused.
#1 Best Overall
How many people were potentially affected?
CSC’s notice to the California attorney general identified approximately 5,678 California residents who may have been impacted. CyberScoop reported the figure as 5,678 affected customers; CSC’s filing’s qualification is important: it gives a potentially affected population, not proof that each person’s information was accessed or used.
What did CSC say it did after discovering the incident?
CSC said it stopped the activity, notified law enforcement, and engaged two independent cybersecurity firms. It also described security measures it had implemented or advanced:
- Two-factor authentication on certain customer-facing applications and internal administrative logins.
- Expanded firewalls.
- Sixteen-character employee passwords.
The filing said there was no evidence of current or ongoing unauthorized access when CSC submitted the notice. It does not name the cybersecurity firms.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesWhat support did the 2018 notice offer?
CSC said it would notify potentially impacted individuals and provide 12 months of credit monitoring and identity restoration at no cost. The sample notification letter named AllClear ID and gave guidance on reviewing credit reports, placing fraud alerts, and requesting security freezes. These were terms of the 2018 notification, not an offer shown to be available today.
Why did the notice appear in California’s breach database?
California says businesses and public agencies must notify residents when covered unencrypted personal information was acquired, or reasonably believed to have been acquired, by an unauthorized person. For incidents affecting more than 500 California residents, the state also requires a sample notice to be submitted to the attorney general. That filing requirement explains why the CSC notice appears in the state’s records; it is not, by itself, a finding of liability or proof of a specific security failure. See the California attorney general’s breach-reporting guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is this the same as CSC’s later reported incident?
No. A separate incident described in an August 2026 law-firm page concerned data copied from a third-party-hosted database in August 2025, with notifications in August 2026. Those dates and circumstances are distinct from the 2017–2018 breach covered here. The later page is secondary legal-marketing material and should not be used to infer details or current assistance for the earlier incident. The page describing the later incident concerns that separate event.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

