HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Substitute Teacher Service
bd_111021992bf6f556 · schema v1 · pii pii-v1
Full breach record for Substitute Teacher Service →Substitute Teacher Service, Inc. notified the Maryland AG that an unauthorized actor acquired database files containing names, SSNs, driver's license numbers, and financial account info from 138 Maryland residents. The incident was discovered on Jan 9, 2025, with unauthorized access occurring on Dec 22, 2024. Notifications were sent on March 3, 2025, offering 12 months of credit monitoring.
Maryland clock⏱ MD AG >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cicada3301 about this victim predates this filing by 32 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_5c5d2147a4a876d8Leak Sitecicada3301filed 2025-02-08(32d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_30de5097ad118e4dMontana State AGfiled 2025-03-12Candidate
- bd_96fd64d242721c77New Hampshire State AGfiled 2025-03-12Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376538.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 12, 2025
- Raw hash
- 28bcce162868db79057dac7843c3a5e90975696b254a0d48a5871e7d79382763
Reporting entity
- Name
- Substitute Teacher Servicenorm: substitute teacher service
- Domain
- thesubservice.com
Victim entity
- Name
- Substitute Teacher Servicenorm: substitute teacher service
- Domain
- thesubservice.com
Incident
- Discovered
- Jan 9, 2025
- Materiality determined
- —
- Notification sent
- Mar 3, 2025
- Affected individuals
- 138
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- MD AG >30dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.