MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Mount Rogers Community Services
bd_23f14db94863f9f6 · schema v1 · pii pii-v1
Full breach record for Mount Rogers Community Services →Mount Rogers Community Services experienced a ransomware incident discovered on April 29, 2025, with unauthorized access occurring between April 27 and 29, 2025. The breach impacted demographic data, SSNs, clinical/health information, and insurance/claims data. The organization engaged forensic experts, notified federal law enforcement (FBI, CISA), and provided complimentary identity monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9728f98b95b13de4New Hampshire State AGfiled 2025-06-17(4d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-06-13-mount-rogers-community-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2025
- Raw hash
- 0dc7de703ec80cd2399d2b01c51c3d0d7d1488ac8540623f40ea4b16c948c16d
Reporting entity
- Name
- Mount Rogers Community Servicesnorm: mount rogers community
- Domain
- mr-commserv.org
Victim entity
- Name
- Mount Rogers Community Servicesnorm: mount rogers community
- Domain
- mr-commserv.org
Incident
- Discovered
- Apr 29, 2025
- Materiality determined
- Jun 13, 2025
- Notification sent
- Jun 13, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified FBI’s Cyber Crimes DivisionNotified Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA)Notified Cyber Fusion Center of the Virginia State Police
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.