MalwareRansomwareData EncryptedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Young Life Store
bd_20c234e4315af6fb · schema v1 · pii pii-v1
Full breach record for Young Life Store →Young Life notified consumers of a security incident occurring June 13-14, 2024, where malware infected its network and an unauthorized actor accessed files containing PII of employees, dependents, and volunteers. Young Life engaged law enforcement, offered credit monitoring, and is reviewing security policies. No identity theft evidence found. Specific data types obscured in redacted notice, but PII and government IDs implied. Vermont AG notice filed Dec 12, 2024.
Vermont clock✗ VT AG >45 bday26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_220ceb537a6b6b89Maine State AGfiled 2024-12-12Verified
- bd_2cb45b4fa5ab2e70Montana State AGfiled 2024-12-12Verified
- bd_38d3cc83de38e353New Hampshire State AGfiled 2024-12-12Verified
- bd_46d6d7dade86949aWashington State AGfiled 2024-12-12Candidate
Show 2 more filings ↓Show fewer ↑
- bd_57df9102115b8e7dCalifornia State AGfiled 2024-12-12Verified
- bd_a1828be206b7cdbbOregon State AGfiled 2024-12-12Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-12-12-young-life-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2024
- Raw hash
- 1a7ab15cd8566f040a69cdba02b735264b1497544fc08c683b461c475c19bda4
Reporting entity
- Name
- Young Life Storenorm: young life store
- Domain
- younglifestore.com
Victim entity
- Name
- Young Life Storenorm: young life store
- Domain
- younglifestore.com
Incident
- Discovered
- Jun 14, 2024
- Materiality determined
- —
- Notification sent
- Dec 12, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notify applicable regulatory authorities, as required by law
Compliance
- Time to disclose
- 26 weeks(181 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.