HackingStolen CredentialsEmail MisuseData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Scioto County, Ohio
bd_290806988d152211 · schema v1 · pii pii-v1
Full breach record for Scioto County, Ohio →Scioto County, Ohio, notified consumers of a cyber incident where an unauthorized actor accessed three employee email accounts between Jan 24 and Feb 3, 2025. The actor copied contents of one account, exposing personal information (names, addresses) of affected individuals. No financial data was compromised. The County engaged forensic investigators, reset passwords, and offered 1-year Experian identity monitoring.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3c9d4bee71a49e53Maine State AGfiled 2025-04-03Candidate
- bd_46a66d8429332c51Indiana State AGfiled 2025-04-03Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-03-scioto-county-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2025
- Raw hash
- b016af5ec740d22869e459e3d4602f9c651a32831d5aa4ca3088ba6a6c8e5a8c
Reporting entity
- Name
- Scioto County, Ohionorm: scioto county ohio
- Industry
- government_public
Victim entity
- Name
- Scioto County, Ohionorm: scioto county ohio
- Industry
- government_public
Incident
- Discovered
- Feb 3, 2025
- Materiality determined
- —
- Notification sent
- Apr 3, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified all appropriate state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.