MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHigh
Cherry Street Services, Inc.
bd_4665d1e8abdb59eb · schema v1 · pii pii-v1
Full breach record for Cherry Street Services, Inc. →Cherry Street Services, Inc., a healthcare organization, experienced a ransomware attack on December 21, 2023. The breach was discovered on December 24, 2023, and affected 184,372 individuals. The compromised information included names and financial account numbers or credit/debit card numbers along with their security codes. The company provided written notification to affected individuals on January 24, 2024, and April 16, 2024, and offered 12 months of credit monitoring and identity theft protection services through IDX.
Maine clockDiscovered Dec 24, 2023 → Filed with AG Apr 17, 2024115d ✗ ME AG >90d16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b0cafa58dea56bd4Vermont State AGfiled 2024-04-17Verified
- bd_8ed61777b01dc336Indiana State AGfiled 2024-04-16(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/2b5a149e-ee5d-4199-9149-ca4d19ec7515.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2024
- Raw hash
- 37c400d852dca406cb840a02e50b7ad8d279b88dec0ccb6ebdeedc1a03024ac5
Reporting entity
- Name
- Cherry Street Services, Inc.norm: cherry street
Victim entity
- Name
- Cherry Street Services, Inc.norm: cherry street
- Industry
- Healthcare
Incident
- Discovered
- Dec 24, 2023
- Materiality determined
- —
- Notification sent
- Apr 16, 2024
- Affected individuals
- 184,372
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 16 weeks(115 days from discovery to filing)
- Compliance flags
- ME AG >90d · 115dME resident >60d · 114d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 24, 2023→ Filed with AG: Apr 17, 2024115d 90 days ME AG >90d Maine Discovered: Dec 24, 2023→ Notified: Apr 16, 2024114d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.