Social EngineeringPhishingStolen CredentialsDelayed DiscoveryPIIIDENTITY_BASICLowContained
STUDENT TRANSPORTATION OF AMERICA, INC.
bd_120ff8acd6aaf495 · schema v1 · pii pii-v1
Full breach record for STUDENT TRANSPORTATION OF AMERICA, INC. →Student Transportation of America (STA) notified consumers of a security incident discovered on January 24, 2024, where unauthorized actors accessed employee email accounts via suspicious activity. The investigation determined that personal information of certain individuals was potentially impacted. STA engaged forensic specialists, notified law enforcement, enhanced security protocols, and offered 12 months of complimentary credit monitoring. Approximately 130 Rhode Island residents may be affected.
Vermont clock✗ VT AG >45 bday28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0fa8b4c088a6959bMontana State AGfiled 2024-08-08Candidate
- bd_19e309ad87559e21New Hampshire State AGfiled 2024-08-08Verified
- bd_1d705831f299146fIndiana State AGfiled 2024-08-08Verified
- bd_3ad69f7896265a11California State AGfiled 2024-08-08Verified
Show 1 more filing ↓Show fewer ↑
- bd_e8e795c06a880890Maine State AGfiled 2024-08-08Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-08-student-transportation-america-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 8, 2024
- Raw hash
- 547ed8c359beaa3c96c00e85ab78a0eb389020b43966b0e4a8c43add10d7def6
Reporting entity
- Name
- STUDENT TRANSPORTATION OF AMERICA, INC.norm: student transportation of america
- Domain
- ridesta.com
Victim entity
- Name
- STUDENT TRANSPORTATION OF AMERICA, INC.norm: student transportation of america
- Domain
- ridesta.com
Incident
- Discovered
- Jan 24, 2024
- Materiality determined
- —
- Notification sent
- Aug 8, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 weeks(197 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.