DisclosureLens
AccidentalGovernmentGovernmentMisconfigurationCustomer Data InvolvedPIILowContained

Maine.gov

bd_4437c8dbf4bb8515 · schema v1 · pii pii-v1

Severity

Low

Discovered

Oct 14, 2022

Filed

Oct 14, 2022

To disclose

≤1 day

Affected

0scope not determined

Confidence

50%
Full breach record for Maine.gov

A security researcher discovered that a File Transfer Protocol (FTP) server belonging to maine.gov was publicly accessible, leading to an inadvertent disclosure of information. The exposed data included user information such as names, phone numbers, and email communications, as well as details about state projects.

Maine clockDiscovered Oct 14, 2022Filed with AG Oct 14, 20220d ME AG ≤30d≤1 day discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · ≤1 day / 0 days

Oct 14, 2022

Begins

Oct 14, 2022

Discovered

Oct 14, 2022

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.