Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICCREDENTIALSLowContained
Catholic Diocese of Cleveland
bd_21ddc3aa2c09650b · schema v1 · pii pii-v1
Full breach record for Catholic Diocese of Cleveland →The Catholic Diocese of Cleveland notified consumers of a data breach involving unauthorized access to an employee's email account between December 14, 2023, and January 12, 2024. The incident likely exposed names and additional personal data. The Diocese engaged forensic investigators, contained the breach, and is offering 12 months of credit monitoring via Experian IdentityWorks to affected individuals.
Vermont clock✗ VT AG >45 bday15 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0d35c1a84a132ff7Indiana State AGfiled 2024-04-29Verified
- bd_8e8c782f32766d3cMontana State AGfiled 2024-04-22(7d gap)Candidate
- bd_e8e6f12187ab27d3Maine State AGfiled 2024-04-22(7d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-29-catholic-diocese-cleveland-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 29, 2024
- Raw hash
- ebfd553acee576e1405ae71be088f0a00697928991ec96e594680db3db2f42db
Reporting entity
- Name
- Catholic Diocese of Clevelandnorm: catholic diocese of cleveland
Victim entity
- Name
- Catholic Diocese of Clevelandnorm: catholic diocese of cleveland
Incident
- Discovered
- Jan 12, 2024
- Materiality determined
- —
- Notification sent
- Apr 8, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 weeks(108 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.