HackingProfessional ServicesProfessional ServicesCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
Haymaker Enterprises
bd_014dc4cd77f51bff · schema v1 · pii pii-v1
Full breach record for Haymaker Enterprises →Haymaker Enterprises d/b/a Triage Staffing reported a data breach stemming from a third-party vendor, Aya Healthcare, a healthcare staffing contractor. An unauthorized actor viewed and obtained Triage files from Aya Healthcare's network. The breach occurred on May 1, 2025 and was discovered on June 13, 2025. Data affected included name, date of birth, and Social Security number of 43 Maine residents. Notification letters were mailed July 7, 2025, and one year of credit monitoring was offered.
Maine clockDiscovered Jun 13, 2025 → Filed with AG Jul 7, 202524d ✓ ME AG ≤30d24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_57454f38416a77c1Montana State AGfiled 2025-07-07Candidate
- bd_96b9488f07b11bf4New Hampshire State AGfiled 2025-07-07Verified
- bd_adb98e02d9b2934dVermont State AGfiled 2025-07-07Verified
- bd_1b41cc631dbd47abTexas State AGfiled 2025-07-08(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/922bb17e-1c54-428f-91da-b7b6047b8c31.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2025
- Raw hash
- a79dedcea57627d2a7bd676420afc51ddd86e24175219d31b40fbc5f5aefbb1a
Reporting entity
- Name
- Haymaker Enterprisesnorm: haymaker enterprises
- Industry
- Other Commercial
Victim entity
- Name
- Haymaker Enterprisesnorm: haymaker enterprises
- Industry
- Other Commercial
- Industry
- Professional Servicesllm
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- —
- Notification sent
- Jul 7, 2025
- Affected individuals
- 43
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1213 Data from Information Repositories
- Threat actor
- External
- Third party
- via Aya Healthcare
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 13, 2025→ Filed with AG: Jul 7, 202524d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.