HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Bridges Hospice
bd_0da26962cbbba4c6 · schema v1 · pii pii-v1
Full breach record for Bridges Hospice →Bridges Experience, Inc. disclosed a security incident where unauthorized parties accessed employee email accounts between Dec 2, 2024, and Jan 22, 2025. The breach exposed names and Social Security Numbers of affected individuals. Bridges EXP engaged outside cybersecurity professionals, contained the incident, and offered one year of Equifax Credit Watch Gold monitoring. The incident status is contained.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_12807c4a6d92e71bOregon State AGfiled 2025-06-26Candidate
- bd_1449f67808f2bce5Vermont State AGfiled 2025-06-26Verified
- bd_229a42b3a6021fc6Indiana State AGfiled 2025-06-26Verified
- bd_3db6a39547dc7f08Montana State AGfiled 2025-06-26Verified by operator
Show 4 more filings ↓Show fewer ↑up to 5d gap
- bd_4a3806f82b493cfaCalifornia State AGfiled 2025-06-26Verified
- bd_55d07a6af1f99a5cWashington State AGfiled 2025-06-26Verified by operator
- bd_64e4f040a8df019cNew Hampshire State AGfiled 2025-06-30(4d gap)Verified
- bd_1ef98a8f5a0c9efaTexas State AGfiled 2025-07-01(5d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/Bridges-Adult-SSN_Redacted.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2025
- Raw hash
- 383e7aecfa7436a353fae0caa64045f8db470f90b0f5c18b76bace3ec7bb6649
Reporting entity
- Name
- Bridges Hospicenorm: bridges hospice
- Domain
- bridgeshospice.org
Victim entity
- Name
- Bridges Hospicenorm: bridges hospice
- Domain
- bridgeshospice.org
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.