HackingPIIIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Rochester Philharmonic Orchestra
bd_253bda8c448c14ad · schema v1 · pii pii-v1
Full breach record for Rochester Philharmonic Orchestra →Rochester Philharmonic Orchestra notified Massachusetts residents of a data security incident on May 27, 2026. The breach involved unauthorized access to personal information, including Social Security Numbers and names. The organization is offering 24 months of complimentary identity protection services through IDX to affected individuals.
Leak gap clock✗ Leak >180d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 5 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 198 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_a657d39e33120bb9Leak Siteakirafiled 2025-11-25(157d gap)Verified
- bd_3e1555b835a5290aLeak Siteakirafiled 2025-10-15(198d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_74744a5301dae892Indiana State AGfiled 2026-05-27(26d gap)Verified by operator
- bd_c1c85951f3e733f2Maine State AGfiled 2026-05-28(27d gap)Verified by operator
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-863-rochester-philharmonic-orchestra/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- f7a03aa397c57b391b61e59b000b66a2eea643512307db7f65dd0371408ac8f3
Reporting entity
- Name
- Rochester Philharmonic Orchestranorm: rochester philharmonic orchestra
- Domain
- rpo.org
Victim entity
- Name
- Rochester Philharmonic Orchestranorm: rochester philharmonic orchestra
- Domain
- rpo.org
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 27, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- Leak >180d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.