HackingStolen CredentialsTargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Aya Healthcare
bd_1feaf1979c4f4091 · schema v1 · pii pii-v1
Full breach record for Aya Healthcare →Aya Healthcare, Inc. notified Maryland AG of a data security incident where unauthorized third parties used stolen credentials (obtained from unrelated sources) to access user accounts. The breach involved automated bot access to limited personal information including names, contact info, SSNs, and nursing license numbers. Aya reset passwords and offered 24 months of credit monitoring.
Maryland clock⏱ MD AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_004fdddbe9969934Indiana State AGfiled 2025-02-27Verified
- bd_1e9f96661e12cc26Montana State AGfiled 2025-02-27Candidate
- bd_514b32eabd91432cMaine State AGfiled 2025-02-27Verified
- bd_a9f3734972f43502Vermont State AGfiled 2025-02-27Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376426.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2025
- Raw hash
- 8c437296add4b70538cb046f9f143765331f93725f90914387561e9e8a02034e
Reporting entity
- Name
- Aya Healthcarenorm: aya healthcare
- Domain
- ayahealthcare.com
Victim entity
- Name
- Aya Healthcarenorm: aya healthcare
- Domain
- ayahealthcare.com
Incident
- Discovered
- Jan 12, 2025
- Materiality determined
- —
- Notification sent
- Feb 27, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.