HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Civil Service Employees Association, Inc., Local 1000, AFSCME, AFL-CIO
bd_3c33615cec86aa28 · schema v1 · pii pii-v1
Full breach record for Civil Service Employees Association, Inc., Local 1000, AFSCME, AFL-CIO →Civil Service Employees Association, Inc., Local 1000, AFSCME, AFL-CIO notified consumers of a cybersecurity incident discovered on May 30, 2025. Unauthorized access occurred between May 3 and May 31, 2025, resulting in the theft of names and Social Security Numbers. The organization engaged cybersecurity professionals, took systems offline, and reported the incident to government agencies.
Vermont clock✗ VT AG >45 bday34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_302889683ab05c6dMaine State AGfiled 2026-01-20Candidate
- bd_3a7f8cfb83f1bfffIndiana State AGfiled 2026-01-20Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-01-20-civil-service-employees-association-inc-local-1000-afscme-afl-cio-data-breach-notice
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 20, 2026
- Raw hash
- 588c9dc8877c97ce702d437b016875872d6a8026f3d80e6331016615c3b6ba3b
Reporting entity
- Name
- Civil Service Employees Association, Inc., Local 1000, AFSCME, AFL-CIOnorm: civil service employees association inc local 1000 afscme afl cio
Victim entity
- Name
- Civil Service Employees Association, Inc., Local 1000, AFSCME, AFL-CIOnorm: civil service employees association inc local 1000 afscme afl cio
Incident
- Discovered
- May 30, 2025
- Materiality determined
- Jan 20, 2026
- Notification sent
- Jan 20, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reporting the Incident to relevant government agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 34 weeks(235 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.