DisclosureLens
Social EngineeringTransportation & LogisticsTransportationPhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDFinancial accountMediumContained

Tidewater Transit Company

bd_04cdcb9ff060427c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 1, 2017

Filed

Apr 13, 2017

To disclose

6 weeks

Affected

1state residents only

Confidence

66%
Full breach record for Tidewater Transit Company

Tidewater Transit Co., Inc. notified employees in Montana of a security incident in late March 2017 where employees were targeted by tax-related identity theft, likely via phishing. The incident involved unauthorized use of personal information (SSN, DOB, driver's license) to file fraudulent tax returns. The company engaged Kroll for one year of identity monitoring services.

Incident timeline

discovery → filing · 6 weeks / 43 days

Mar 1, 2017

Discovered

Apr 13, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.