MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Houston Housing Authority
bd_58e7c64814f0b8f5 · schema v1 · pii pii-v1
Full breach record for Houston Housing Authority →Houston Housing Authority (HHA) notified the Maryland Attorney General on March 27, 2025, regarding a cyber-attack discovered on September 22, 2024. An unknown third party accessed HHA systems, encrypted files, and exfiltrated personal information including SSNs, driver's licenses, financial account numbers, and health data. 19 Maryland residents were notified. HHA engaged law enforcement, enhanced technical security, and offered 12 months of credit monitoring.
Leak gap clock✗ Leak >180d19 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed19 affectedView incident
A leak claim by meow about this victim predates this filing by 538 days.View originating leak claim
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376761.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- e08b6f98ba50b9b59a91b1b518a5942f9dd8c1c1d1071493107a25bdb4aec293
Reporting entity
- Name
- Polsinelli (on behalf of Houston Housing Authority)norm: polsinelli on behalf of houston housing authority
Victim entity
- Name
- Houston Housing Authoritynorm: houston housing authority
- Domain
- housingforhouston.com
- Industry
- government_public
Incident
- Discovered
- Sep 22, 2024
- Materiality determined
- —
- Notification sent
- Mar 27, 2025
- Affected individuals
- 19
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
Compliance
- Time to disclose
- 19 months(578 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.