MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Appalachian Regional Commission
bd_1a0a528fe9e9caed · schema v1 · pii pii-v1
Full breach record for Appalachian Regional Commission →Appalachian Regional Commission notified Vermont AG of a cybersecurity incident on April 10, 2025, involving malware deployment and unauthorized data access. Personal information including names, SSNs, and medical data may have been compromised. ARC engaged forensic investigators, contacted law enforcement, and is offering 24 months of credit monitoring.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 96 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_07c7c538d3cc209aMaine State AGfiled 2025-07-15Candidate
- bd_c52276d3217148adIndiana State AGfiled 2025-07-15Verified
- bd_465cb0871721c557New Hampshire State AGfiled 2025-07-16(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-15-appalachian-regional-commission-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2025
- Raw hash
- ec870e1218e2ffcba14c0b46f6eb860120e35acf4d05242a1456e4d1a24f9b6a
Reporting entity
- Name
- Appalachian Regional Commissionnorm: appalachian regional commission
- Domain
- arc.gov
Victim entity
- Name
- Appalachian Regional Commissionnorm: appalachian regional commission
- Domain
- arc.gov
Incident
- Discovered
- Apr 10, 2025
- Materiality determined
- Jul 15, 2025
- Notification sent
- Jul 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- contacted law enforcement
Compliance
- Time to disclose
- 14 weeks(96 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.