YMCA of Southern Maine
bd_3511d4a1951e3529 · schema v1 · pii pii-v1
Full breach record for YMCA of Southern Maine →YMCA of Southern Maine notified Massachusetts residents of a security incident impacting names, SSNs, DOBs, addresses, and direct deposit info. The breach involved unauthorized access, likely via credential compromise. The organization reset passwords, restored systems, deployed endpoint detection, and offered 24 months of credit monitoring via TransUnion. No evidence of misuse was found. Notification date: July 14, 2026.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jul 21, 2026
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_59e36d2a84067ed92026-07-20 · +1dVerified
- Vermont State AGbd_b116a19e93e0a0872026-07-14 · +7dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jul 14 (VT), last Jul 21 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.