HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Pennsylvania State Education Association
bd_410f8f4728a91437 · schema v1 · pii pii-v1
Full breach record for Pennsylvania State Education Association →Pennsylvania State Education Association (PSEA) notified the New Hampshire Attorney General of a data security incident occurring on or about July 6, 2024. An unauthorized actor accessed PSEA's network, impacting personal information of approximately 67 New Hampshire residents. PSEA discovered the incident on February 18, 2025, engaged external cybersecurity professionals, and began providing substitute notice (including credit monitoring) on March 17, 2025.
Leak gap clock✗ Leak >180d28 days discovery → filing
This filing is one of 3 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 255 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b6cf1deaa264fa8aMaryland State AGfiled 2025-03-18Candidate
- bd_ab8d33219fbbcab5Vermont State AGfiled 2025-03-19(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pennsylvania-state-education-association-20250318.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 18, 2025
- Raw hash
- c3269c213903cfcfa436517b97ed7e4b3e65a9ed9ac2bf469290ee903e6972eb
Reporting entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Victim entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Incident
- Discovered
- Feb 18, 2025
- Materiality determined
- —
- Notification sent
- Mar 17, 2025
- Affected individuals
- 67
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.