Valley Regional Transit
bd_5bbda4e6f2ce65d8 · schema v1 · pii pii-v1
Full breach record for Valley Regional Transit →Valley Regional Transit (VRT) experienced a ransomware attack in October 2021. Cybercriminals exfiltrated data before encrypting systems. The breach affected approximately 477 Idaho residents, exposing names, dates of birth, addresses, Social Security numbers, driver's license numbers, and one payment card number. VRT engaged forensic experts, contained the malware, and is offering credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 18, 2021
Begins
Jan 14, 2022
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_1d005beea990e2072022-01-21 · +7dVerified
- Massachusetts State AGbd_4f4d74fbdd5c0fb72022-01-25 · +11dVerified
- Idaho State AGLockBit 2.0bd_76e9b90595f5b3242021-10-19 · +87dCandidate
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Oct 19 (ID), last Jan 25 (MA) — a 98-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.