HackingStolen CredentialsCapture Stored DataData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSMediumContained
City of Hayward, Minnesota
bd_31b23c8ba48b2281 · schema v1 · pii pii-v1
Full breach record for City of Hayward, Minnesota →City of Hayward notified the Maryland Attorney General of a data security incident occurring on July 9, 2023. An unauthorized actor downloaded files containing personal information, including names, SSNs, financial account numbers, and medical data. The incident affected approximately 173 Maryland residents. The City engaged external cybersecurity professionals, notified the FBI, and is offering 12 months of credit monitoring to affected individuals.
Maryland clock✓ MD AG ≤30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_07b9796ec86c247fCalifornia State AGfiled 2025-01-29Verified
- bd_23584d2513e0424fIndiana State AGfiled 2025-01-29Verified
- bd_c85af40eea4341b4New Hampshire State AGfiled 2025-01-29Verified
- bd_e6c7af17315c5953Vermont State AGfiled 2025-01-29Verified
Show 2 more filings ↓Show fewer ↑up to 2d gap
- bd_ebf17f268801e42bMontana State AGfiled 2025-01-29Verified
- bd_999d64041fc82d93Maine State AGfiled 2025-01-31(2d gap)Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376261.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2025
- Raw hash
- d0d0fb40c0126e1f898392f8e02c82dbae99ace1bde9c2645782b5c2384068c6
Reporting entity
- Name
- City of Hayward, Minnesotanorm: city of hayward minnesota
Victim entity
- Name
- City of Hayward, Minnesotanorm: city of hayward minnesota
Incident
- Discovered
- Dec 30, 2024
- Materiality determined
- —
- Notification sent
- Jan 29, 2025
- Affected individuals
- 173
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI of the incident
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- MD AG ≤30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.