HackingData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
CITY OF HOPE
bd_56c727d6f5a7adc5 · schema v1 · pii pii-v1
Full breach record for CITY OF HOPE →City of Hope notified Vermont AG of a data breach occurring between Sept 19 and Oct 12, 2023. Unauthorized third parties accessed systems and exfiltrated files containing PII, SSNs, financial data, and PHI. City of Hope engaged a cybersecurity firm, reported to law enforcement, and provided two years of Kroll identity monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_4e34f10272b1cbb2New Hampshire State AGfiled 2024-04-02Verified
- bd_512fd9d9da2e106bMontana State AGfiled 2024-04-02Candidate
- bd_646c0dd6c4c8efeeCalifornia State AGfiled 2024-04-02Verified
- bd_a206c1ef5bf16daeWashington State AGfiled 2024-04-02Verified
Show 3 more filings ↓Show fewer ↑up to 14d gap
- bd_eacec21685bd1ec2Maine State AGfiled 2024-04-02Verified
- bd_9a6d405cfd05175cOregon State AGfiled 2024-04-03(1d gap)Verified
- bd_2b407412ec00741dOregon State AGfiled 2024-04-16(14d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-02-city-hope-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2024
- Raw hash
- 998eab26c235f6b3c4031e7d7b9a79e6e1d6a67c46b149b1e01dc806dcf0b37f
Reporting entity
- Name
- CITY OF HOPEnorm: city of hope
- Domain
- cityofhope.org
Victim entity
- Name
- CITY OF HOPEnorm: city of hope
- Domain
- cityofhope.org
Incident
- Discovered
- Oct 13, 2023
- Materiality determined
- —
- Notification sent
- Apr 2, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- notified regulatory bodies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(172 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.