HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Diocese of Lansing
bd_16c6167e7fec658a · schema v1 · pii pii-v1
Full breach record for Diocese of Lansing →The Diocese of Lansing reported a data breach involving the MoveIT transfer application. The incident occurred on May 31, 2023, and was discovered on November 30, 2023. Approximately 4,124 individuals were affected, including one Maine resident. The breach compromised names and Social Security Numbers. The Diocese provided 12 months of credit monitoring and identity restoration services through Experian.
Maine clockDiscovered Nov 30, 2023 → Filed with AG Jan 30, 202461d ⏱ ME AG >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_21b0dc93995636f8Indiana State AGfiled 2024-01-30Verified
- bd_717ad9593977e165Indiana State AGfiled 2024-01-12(18d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1a06a19c-5ab8-4b2c-9e93-09118061f7af.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2024
- Raw hash
- 447ada03f579748d99af528a012e83d2ae7fb54c74fb9ed79402fb77d923806c
Reporting entity
- Name
- Diocese of Lansingnorm: diocese of lansing
- Domain
- dioceseoflansing.org
Victim entity
- Name
- Diocese of Lansingnorm: diocese of lansing
- Domain
- dioceseoflansing.org
Incident
- Discovered
- Nov 30, 2023
- Materiality determined
- —
- Notification sent
- Jan 30, 2024
- Affected individuals
- 4,124
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- ME AG >30d · 61dME resident >60d · 61d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Nov 30, 2023→ Filed with AG: Jan 30, 202461d 30 days (soft) ME AG >30d Maine Discovered: Nov 30, 2023→ Notified: Jan 30, 202461d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.