Appalachian Regional Commission
bd_465cb0871721c557 · schema v1 · pii pii-v1
Full breach record for Appalachian Regional Commission →Appalachian Regional Commission (ARC) notified the NH Attorney General of a cybersecurity incident discovered on April 10, 2025, involving malware deployment and unauthorized data access/exfiltration. One New Hampshire resident was affected, with potential exposure of name, address, SSN, bank account/routing numbers, and medical information. ARC contained the threat, engaged forensic investigators, contacted law enforcement, and is offering 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 10, 2025
Begins
Apr 10, 2025
Discovered
Jul 16, 2025
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitemedusabd_3b6377441539e4122025-04-24 · +83dVerified by operator
- Leak Sitemedusabd_fd86c5fa76b5eb3e2025-04-10 · +97dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_07c7c538d3cc209a2025-07-15 · +1dCandidate
- Nebraska State AGbd_0c6bfea17a31825a2025-07-15 · +1dVerified
- Vermont State AGbd_1a0a528fe9e9caed2025-07-15 · +1dVerified by operator
- Indiana State AGbd_c52276d3217148ad2025-07-15 · +1dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 1d gap
- Massachusetts State AGbd_e3bc9e8c6362efb82025-07-15 · +1dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.