DisclosureLens
MalwareGovernmentGovernmentRansomwareData ExfiltratedTargetedCustomer Data InvolvedEmployee Data InvolvedAuthenticationCredentialsEducationFinancial accountHealth (basic)Identity (basic)Government IDMinorPHIHighContained

Asotin County Public Facilities District

bd_3582930b21ca8ddc · schema v1 · pii pii-v1

Severity

High

Discovered

May 31, 2022

Filed

Feb 15, 2023

To disclose

37 weeks

Affected

1,090state residents only

Confidence

71%
Full breach record for Asotin County Public Facilities District

Asotin County Public Facilities District (WA) reported a ransomware cyberattack occurring between April 4 and May 31, 2022. The incident affected 1,090 Washington residents, exposing PII including SSNs, driver's licenses, financial account data, and health information. ACPFD engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring via Experian.

Washington clock WA AG >90d37 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 57 days
discovery → filing · 37 weeks / 260 days

Apr 4, 2022

Begins

May 31, 2022

Discovered

Feb 15, 2023

Filed

vs. sector median

+26 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,090 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.