Appalachian Regional Commission
bd_1a0a528fe9e9caed · schema v1 · pii pii-v1
Full breach record for Appalachian Regional Commission →The Appalachian Regional Commission (ARC) notified consumers of a data security incident involving malware deployment on April 10, 2025. An unauthorized party accessed and removed data, including names, addresses, dates of birth, Social Security numbers, driver's license/state ID numbers, and potentially medical or treatment information. ARC contained the threat, engaged forensic investigators, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 10, 2025
Begins
Apr 10, 2025
Discovered
Jul 15, 2025
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitemedusabd_3b6377441539e4122025-04-24 · +82dVerified by operator
- Leak Sitemedusabd_fd86c5fa76b5eb3e2025-04-10 · +96dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_07c7c538d3cc209a2025-07-15Candidate
- Nebraska State AGbd_0c6bfea17a31825a2025-07-15Verified
- Indiana State AGbd_c52276d3217148ad2025-07-15Verified by operator
- Massachusetts State AGbd_e3bc9e8c6362efb82025-07-15Verified by operator
Show 1 more filing ↓Show fewer ↑up to 1d gap
- New Hampshire State AGbd_465cb0871721c5572025-07-16 · +1dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.