HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumActive
Kenneth Young Center
bd_15c56e2f063d0007 · schema v1 · pii pii-v1
Full breach record for Kenneth Young Center →Kenneth Young Center notified Vermont AG of a March 6, 2024 data breach where an unauthorized actor accessed systems and potentially viewed employee data including SSNs, driver's licenses, financial accounts, passports, and medical info. Investigation ongoing. Center engaged outside assistance, notified federal law enforcement, enhanced security controls, and offered 24 months of credit monitoring via Experian.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_b7e68ea8846c071dLeak Sitemedusafiled 2024-03-11(27d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_63c881757b803197Indiana State AGfiled 2024-04-08Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-08-kenneth-young-center-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2024
- Raw hash
- 1792deb1841d27273111a469c3fb83e664dbf23177af0631a25c7d14bc50ea92
Reporting entity
- Name
- Kenneth Young Centernorm: kenneth young center
- Domain
- kennethyoung.org
Victim entity
- Name
- Kenneth Young Centernorm: kenneth young center
- Domain
- kennethyoung.org
Incident
- Discovered
- Mar 6, 2024
- Materiality determined
- —
- Notification sent
- Apr 8, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.