HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Substitute Teacher Service
bd_126e3a2896b55268 · schema v1 · pii pii-v1
Full breach record for Substitute Teacher Service →Substitute Teacher Service, Inc. notified employees of a data security event where an unauthorized actor accessed database files containing names, SSNs, driver's license numbers, and financial account details. The incident was discovered on January 9, 2025, following suspicious activity. STS engaged forensic teams and is offering 12 months of credit monitoring.
Leak gap clock⏱ Leak >30d13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cicada3301 about this victim predates this filing by 61 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_05ca8d0db65cf27cDelaware State AGfiled 2025-03-03(38d gap)Candidate
- bd_5e41e7fee095d80bIndiana State AGfiled 2025-03-03(38d gap)Verified
- bd_86443b1040eb4e9eDelaware State AGfiled 2025-03-03(38d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2025/04/STS-Employee-Notice-Letter_Redacted.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 10, 2025
- Raw hash
- 1606278f3d31af360084bb5a07da2620bda9d966ce4d2caffbcc05642cd219bc
Reporting entity
- Name
- Substitute Teacher Servicenorm: substitute teacher service
- Domain
- thesubservice.com
Victim entity
- Name
- Substitute Teacher Servicenorm: substitute teacher service
- Domain
- thesubservice.com
Incident
- Discovered
- Jan 9, 2025
- Materiality determined
- —
- Notification sent
- Apr 10, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.