California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.
Social Engineering Examples·3 sources
Undercover investigators for the California Attorney General and six county district attorneys inspected dumpsters at 16 Kaiser Permanente facilities statewide and found hundreds of items of hazardous and medical waste (aerosols, cleansers, sanitizers, batteries, electronic waste, syringes, medical tubing with body fluids, and pharmaceuticals) alongside more than 10,000 paper records containing information for over 7,700 patients, all sitting in unsecured dumpsters bound for public landfills.
The conduct was alleged to date back to 2015. California DOJ announced a $49 million settlement on September 8, 2023, with final judgment signed October 13, 2023, resolving claims that Kaiser improperly disposed of hazardous waste, medical waste, and protected patient health information without admission of liability.
This is not an attacker-driven social-engineering incident in the classic sense; it is an internal-control failure that created the same exposure a dumpster-diving attacker would exploit. Over a period investigators trace back to 2015, Kaiser facilities across California allegedly placed regulated hazardous waste, medical waste, and paper records containing protected health information (PHI) into ordinary, unsecured dumpsters and compactors headed for public landfills, rather than segregating and handling them through required hazardous-waste and PHI-destruction channels.
California's Attorney General, working with district attorneys in six counties (Alameda, San Bernardino, San Francisco, San Joaquin, San Mateo, and Yolo), built the case using undercover inspections of dumpsters at 16 Kaiser facilities statewide. Those inspections documented hundreds of items of hazardous and medical waste (aerosols, cleansers, sanitizers, batteries, electronic waste, syringes, medical tubing with body fluids, and pharmaceuticals) sitting in publicly accessible trash destined for landfill, alongside more than 10,000 paper records containing information belonging to over 7,700 patients.
Because the waste was in unsecured, publicly accessible dumpsters, it was functionally exposed to exactly the same risk that a real-world dumpster-diving adversary (identity thief, competitor, or social engineer building a pretext from patient/employee data) would exploit to harvest sensitive personal and health information or hazardous materials.
Not applicable: this was not a lure/pretext-based social engineering attack but a documented pattern of improper waste-disposal practices that exposed patient PHI and hazardous/medical waste to public access via unsecured dumpsters, the same exposure vector dumpster-diving attackers rely on.
California Attorney General Rob Bonta announced a $49 million settlement with Kaiser on September 8, 2023; the parties' stipulation was entered on or about September 7, 2023, and the final judgment was signed October 13, 2023. Kaiser did not admit or deny liability under the proposed stipulated judgment (a consent resolution of disputed claims). Beyond the monetary penalty, Kaiser is subject to a 5-year injunctive compliance program including independent audits, mandatory trash and field audits, staff training, a compliance hotline, and explicit bans on placing hazardous waste or PHI in landfill-bound dumpsters.
This case demonstrates that dumpster-diving exposure risk is not solely an attacker-initiated technique: it is frequently created by an organization's own disposal failures, turning ordinary trash into a passive but massive data-breach and hazardous-materials incident. For a healthcare system the size of Kaiser, unsecured dumpsters accessible to the public represent a real-world "walk-up" attack surface for identity thieves, medical-record fraud, or social engineers seeking authentic-looking PHI to build pretexts; the $49 million penalty and 5-year audit regime underscore how regulators now treat physical document/waste security with the same seriousness as digital breach controls under HIPAA-adjacent state enforcement.
Settlement's injunctive terms function as the corrective control set: independent third-party auditor; minimum 520 trash audits over 5 years (120 in year 1, 100/year thereafter); minimum 40 programmatic field audits per year for 5 years; quarterly trash-audit reports and semiannual field-audit reports to regulators; local facility oversight officers plus regional privacy/security officers; annual training for personnel handling hazardous waste, medical waste, and PHI (new PHI-handling staff trained within 30 days); a third-party compliance hotline for PHI-disposal complaints; and explicit prohibitions on placing hazardous waste, universal waste, or PHI in dumpsters/compactors, with required labeling, storage, disposal, and recordkeeping standards.
General lessons for any organization: secure/lock waste receptacles that may hold PHI or hazardous materials, shred or otherwise destroy paper PHI before disposal, classify and segregate hazardous/medical waste streams from ordinary trash, and audit disposal practices at the facility level rather than assuming corporate policy is being followed on the ground.
Social Engineering Examples. “Kaiser Permanente Medical Waste and Patient Records Dumpster-Disposal Settlement”. Accessed 19 September 2026. https://socialengineeringexamples.com/kaiser-permanente-medical-waste-dumping-settlement-2023
a dumpster-diving adversary exploiting this type of exposure would typically scout facility grounds and trash-collection routines (dumpster/compactor type, pickup days, fencing, lighting, and lock status) using casual observation or publicly available site information, consistent with how investigators in this case identified 16 Kaiser facilities with unsecured, publicly accessible dumpsters.
facility grounds, dumpster placement, and pickup schedules are inherently observable from public property and are very hard to fully conceal, so the realistic control shifts to Stage 2, hardening physical access to the receptacles themselves.
the adversary would exploit unlocked or unenclosed dumpsters and compactors sitting in public or semi-public areas (parking lots, loading docks) to physically retrieve discarded material without breaching any building or bypassing access controls, the same exposure the Attorney General's undercover inspectors documented at Kaiser sites.
locking, fencing, or enclosing dumpsters and compactors and restricting access to collection areas, as the settlement's injunctive terms require, removes the walk-up access that made retrieval possible in the first place.
once inside the receptacle, an adversary would sift mixed trash to separate valuable items, paper records bearing PHI, labeled prescription bottles, billing documents, from ordinary waste, comparable to how investigators catalogued more than 10,000 patient records and hundreds of hazardous/medical waste items mixed into ordinary landfill-bound trash.
segregating hazardous, medical, and PHI-bearing waste from ordinary trash streams at the point of generation, required by the settlement's waste-classification and dedicated-container mandates, prevents sensitive material from ever reaching a general-purpose dumpster where an outsider could triage it.
the adversary would read or photograph unredacted patient records (names, addresses, medical history, insurance and billing detail) to compile identity-theft or medical-fraud dossiers, or to build authentic-sounding pretexts for follow-on social-engineering attempts against patients or the healthcare provider.
shredding, pulping, or otherwise rendering paper PHI unreadable before disposal, required under Civil Code section 56.101 and the settlement's PHI-destruction terms, eliminates usable data even if an adversary reaches the discarded material.
harvested PHI and personal data would typically be used or resold for medical identity theft, insurance or prescription fraud, or as raw material for phishing or vishing pretexts that reference real patient or employee details to appear credible.
downstream monetization of stolen PHI is largely outside the originating organization's control once data has been extracted, so the realistic controls remain upstream at Stages 2 through 4, preventing extraction in the first place, backed by breach notification and patient-remediation processes if exposure still occurs.
independent of any data theft, the physically exposed hazardous and medical waste (needles, body-fluid-contaminated tubing, pharmaceuticals) documented in the unsecured dumpsters created a direct public-health and environmental risk to anyone accessing the same bins, a harm regulators treated as seriously as the PHI exposure.
proper hazardous and medical waste segregation, labeling, and transport via a licensed hauler, independently required by California's Hazardous Waste Control Law and Medical Waste Management Act and reinforced by the settlement's injunctive terms, keeps regulated waste out of public landfill-bound containers entirely.
undercover government investigators, not a criminal actor, exploited this identical access to document the exposure, leading to the $49 million enforcement settlement; for a real dumpster-diving adversary the parallel end state is successful extraction of exploitable data or materials before facility staff or law enforcement intervene.
recurring independent audits (the settlement mandates no fewer than 520 trash audits and 40 programmatic field audits per year for five years), plus mandatory staff training and a third-party compliance hotline, catch violations on an ongoing basis rather than relying on a one-time undercover inspection to surface the exposure.
Browse by what this case has in common with others in the library.
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing all ~11,000 staff W-2s to…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…