HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Muscatine Power and Water
bd_3ff8d8ed8e32d61d · schema v1 · pii pii-v1
Full breach record for Muscatine Power and Water →Muscatine Power and Water notified consumers of a cybersecurity incident on January 26, 2024, where an unauthorized party briefly accessed its corporate network. Exposed data included names, Social Security Numbers, and CPNI (telephone billing details). The company engaged forensic investigators, secured the network, and offered 12 months of credit monitoring. No identity theft has been reported.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1ce260ae33fa4ad0Montana State AGfiled 2024-03-01Candidate
- bd_9cce6c3130912bb1Maine State AGfiled 2024-03-01Verified
- bd_a4c2d9df6bf3fb69New Hampshire State AGfiled 2024-03-01Verified
- bd_d65b83f288366f91Indiana State AGfiled 2024-03-01Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-03-01-muscatine-power-and-water-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 1, 2024
- Raw hash
- 06485649624dbe1fce32dfb25021d0f62829ce7b7a86176b8f29fab735b9f5e1
Reporting entity
- Name
- Muscatine Power and Waternorm: muscatine power and water
- Industry
- energy_utilities
Victim entity
- Name
- Muscatine Power and Waternorm: muscatine power and water
- Industry
- energy_utilities
Incident
- Discovered
- Jan 26, 2024
- Materiality determined
- Mar 1, 2024
- Notification sent
- Mar 1, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.