HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPIIMediumActive
Council for Relationships, Inc.
bd_162474e3eb0ba7cc · schema v1 · pii pii-v1
Full breach record for Council for Relationships, Inc. →Council for Relationships notified former staff of a data security incident where an unauthorized third party accessed a server containing personal information including SSNs, payroll, and bank details. The incident is under investigation with law enforcement and cyber experts engaged. Affected individuals are offered one year of credit monitoring.
Leak gap clock⏱ Leak >30d≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 2 about the same incident.View merged incident
A leak claim by 8base about this victim predates this filing by 58 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_38a3cdc633201e05Maine State AGfiled 2024-06-12Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-12-council-relationships-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2024
- Raw hash
- 58fa5feed7887b9666f8dfd46872175c22af117cd9c2d7730457164299409b4b
Reporting entity
- Name
- Council for Relationships, Inc.norm: council for relationships
- Domain
- councilforrelationships.org
Victim entity
- Name
- Council for Relationships, Inc.norm: council for relationships
- Domain
- councilforrelationships.org
Incident
- Discovered
- Jun 12, 2024
- Materiality determined
- —
- Notification sent
- Jun 12, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- Leak >30dVT AG ≤14 bday
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.