Lexington & Richland County School District Five
bd_5b524b62ca4f7b55 · schema v1 · pii pii-v1
Full breach record for Lexington & Richland County School District Five →School District Five of Lexington & Richland Counties notified the South Carolina Office of Consumer Affairs on August 29, 2025, regarding a data security incident discovered on June 3, 2025. An external unauthorized individual accessed the District's network and exfiltrated files containing personal information, including names, driver's license numbers, Social Security numbers, and financial account information. The District engaged independent cybersecurity experts, conducted a file review, and is offering 12 months of complimentary credit monitoring and fraud assistance to affected individuals.
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0114b40927dd6457Leak Siteinterlockfiled 2025-06-24(71d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_a60809c6d9840e29Maine State AGfiled 2025-09-02(1d gap)Verified by operator
- bd_ae83edfce1761d09Vermont State AGfiled 2025-09-02(1d gap)Verified
- bd_3a3e2413d556ce50Indiana State AGfiled 2025-08-29(5d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20School%20District%20Five%20Lex-Rich.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 3, 2025
- Raw hash
- be2c333bd9c5ef825e6c82ba7dc82c65121a491eda2836fade8aedf614e112e4
Reporting entity
- Name
- Lexington & Richland County School District Fivenorm: lexington richland county school district five
- Domain
- lexrich5.org
Victim entity
- Name
- Lexington & Richland County School District Fivenorm: lexington richland county school district five
- Domain
- lexrich5.org
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- Aug 29, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.