HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Redwood Coast Regional Center
bd_06c33aec61c448f2 · schema v1 · pii pii-v1
Full breach record for Redwood Coast Regional Center →Redwood Coast Regional Center experienced a data breach on March 6, 2024, involving unauthorized access to systems containing names, SSNs, DOBs, health insurance info, and financial account data. The organization engaged third-party investigators, secured its network, implemented technical safeguards, and offered 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday35 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 245 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2edbb7969dd98f4bMontana State AGfiled 2024-11-04(1d gap)Candidate
- bd_d2aee317976d4d8fCalifornia State AGfiled 2024-11-04(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-05-redwood-coast-regional-center-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2024
- Raw hash
- 194b9571876ac6fe79cb8de70fc9b48142f68fd7c15ca22deb9298328021d79e
Reporting entity
- Name
- Redwood Coast Regional Centernorm: redwood coast regional center
- Domain
- redwoodcoastrc.org
Victim entity
- Name
- Redwood Coast Regional Centernorm: redwood coast regional center
- Domain
- redwoodcoastrc.org
Incident
- Discovered
- Mar 6, 2024
- Materiality determined
- —
- Notification sent
- Nov 5, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 35 weeks(244 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.