HackingStolen CredentialsCapture Stored DataData ExfiltratedTargetedIDENTITY_BASICLowContained
WAYNE COUNTY BANK
bd_0dcf98864eb0562c · schema v1 · pii pii-v1
Full breach record for WAYNE COUNTY BANK →Wayne County, Michigan notified consumers of a data breach identified in late 2024. An unauthorized individual copied files containing personal information (names, etc.) from the network. The county engaged external cybersecurity resources, notified law enforcement, changed passwords, and restored systems from backups. Experian IdentityWorks is offered to affected individuals.
Vermont clock✗ VT AG >45 bday14 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
A leak claim by interlock about this victim predates this filing by 424 days.View originating leak claim
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-22-wayne-county-michigan-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2025
- Raw hash
- 8c8bbea2e5343b62677daa4973caeb9184790dba32e31a6860ce92f290fef319
Reporting entity
- Name
- WAYNE COUNTY BANKnorm: wayne county bank
- Domain
- waynecounty.com
Victim entity
- Name
- WAYNE COUNTY BANKnorm: wayne county bank
- Domain
- waynecounty.com
Incident
- Discovered
- Nov 1, 2024
- Materiality determined
- Oct 15, 2025
- Notification sent
- Dec 22, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(416 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.