HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Encounter for Culture & Education
bd_511702173ddea95e · schema v1 · pii pii-v1
Full breach record for Encounter for Culture & Education →Encounter for Culture & Education notified consumers of a September 4, 2024 cybersecurity incident where two employee email accounts were accessed without authorization. The investigation revealed unauthorized access to certain network files. The organization engaged outside cybersecurity professionals and secured its network. No specific data types were explicitly listed in the provided text snippet, but standard identity protection measures (fraud alerts, credit monitoring) were offered.
Vermont clock✗ VT AG >45 bday46 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7e7e993242f8df7cIndiana State AGfiled 2025-07-23Verified
- bd_fdf02d702404adc5New Hampshire State AGfiled 2025-07-28(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-23-encounter-culture-and-education-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 23, 2025
- Raw hash
- 87f45d0085bd1940969555f37f4246d712f2901e159ebf82372b2c60e3a91121
Reporting entity
- Name
- Encounter for Culture & Educationnorm: encounter for culture education
Victim entity
- Name
- Encounter for Culture & Educationnorm: encounter for culture education
Incident
- Discovered
- Sep 4, 2024
- Materiality determined
- Jul 23, 2025
- Notification sent
- Jul 23, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 46 weeks(322 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.