Appalachian Regional Commission
bd_07c7c538d3cc209a · schema v1 · pii pii-v1
Full breach record for Appalachian Regional Commission →Appalachian Regional Commission (ARC) reported a cybersecurity incident on April 10, 2025, involving malware deployment and unauthorized data access. The breach affected 937 individuals, including 1 Maine resident. Personal information exposed included names, SSNs, driver's licenses, and medical data. ARC engaged forensic investigators, notified law enforcement, and offered 24 months of credit monitoring via IDX.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 10, 2025
Begins
Apr 10, 2025
Discovered
Jul 15, 2025
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitemedusabd_3b6377441539e4122025-04-24 · +82dVerified by operator
- Leak Sitemedusabd_fd86c5fa76b5eb3e2025-04-10 · +96dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Nebraska State AGbd_0c6bfea17a31825a2025-07-15Verified
- Vermont State AGbd_1a0a528fe9e9caed2025-07-15Verified by operator
- Indiana State AGbd_c52276d3217148ad2025-07-15Verified by operator
- Massachusetts State AGbd_e3bc9e8c6362efb82025-07-15Verified by operator
Show 1 more filing ↓Show fewer ↑up to 1d gap
- New Hampshire State AGbd_465cb0871721c5572025-07-16 · +1dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.