MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICLowContained
Association of California School Administrators
bd_05f7dcc0bd140b83 · schema v1 · pii pii-v1
Full breach record for Association of California School Administrators →Association of California School Administrators notified consumers of a September 2023 ransomware incident where an unauthorized actor encrypted files and accessed personal information. The breach impacted names and potentially other data. The organization engaged third-party cybersecurity specialists, conducted a review, and offered 12-24 months of credit monitoring and identity protection services through IDX.
Vermont clock✗ VT AG >45 bday34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_40b3f13958d53462Indiana State AGfiled 2024-05-22Verified
- bd_4d8b08bc7963ab0fNew Hampshire State AGfiled 2024-05-22Verified
- bd_56449ff5993e7e50California State AGfiled 2024-05-22Verified
- bd_724586f861f6bfc4Maine State AGfiled 2024-05-22Candidate
Show 1 more filing ↓Show fewer ↑
- bd_fc9882e474ad594bMontana State AGfiled 2024-05-22Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-22-association-california-school-administrators-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2024
- Raw hash
- 0eb6e3ec67833cd813e179b4733357b73959f2ae8e4512314e2fff0398f2bb90
Reporting entity
- Name
- Association of California School Administratorsnorm: association of california school administrators
Victim entity
- Name
- Association of California School Administratorsnorm: association of california school administrators
Incident
- Discovered
- Sep 24, 2023
- Materiality determined
- May 22, 2024
- Notification sent
- May 22, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 34 weeks(241 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.