MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICLowContained
Red Roof
bd_381f4994cd801f59 · schema v1 · pii pii-v1
Full breach record for Red Roof →Red Roof experienced a ransomware attack on September 23, 2023, resulting in the encryption of a limited subset of data and the copying of a limited amount of data. The copied data included names and a variable data element. Red Roof contained the incident, engaged cybersecurity experts, notified law enforcement, and offered 24 months of credit monitoring and identity theft protection services to affected individuals.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-08-red-roof-inns-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2023
- Raw hash
- 37ba7b496beaef08ecfd2d9846a13b783eedac184d4bcae89f7af0eb58faa4ba
Reporting entity
- Name
- Red Roofnorm: red roof
Victim entity
- Name
- Red Roofnorm: red roof
Incident
- Discovered
- Sep 23, 2023
- Materiality determined
- —
- Notification sent
- Dec 8, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reporting the situation to federal law enforcementreported this incident to relevant government agencies and law enforcement
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.