HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
The Episcopal Church
bd_5bcee5fc74437a1b · schema v1 · pii pii-v1
Full breach record for The Episcopal Church →The Episcopal Church, Domestic and Foreign Missionary Society notified the Maryland Attorney General of a data breach affecting 37 Maryland residents. Unauthorized access occurred between March 25 and April 27, 2024. Affected data included names, SSNs, driver's licenses, financial account numbers, and medical/health insurance information. The Church engaged forensic specialists, notified law enforcement, changed passwords, and offered credit monitoring.
Maryland clock✗ MD AG >90d40 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_605e266749a7eba7Maine State AGfiled 2025-02-05Verified
- bd_a20b51c2f9d250b9New Hampshire State AGfiled 2025-02-05Verified
- bd_c6d052c680ceb727Vermont State AGfiled 2025-02-05Candidate
- bd_e7da2d90ee039989Indiana State AGfiled 2025-02-04(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_d3a899306503e170Montana State AGfiled 2025-02-21(16d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376328.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2025
- Raw hash
- 2e4173fa1aa431c205f58deec2be326288538c1cc898ca295774888d4538cba7
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- The Episcopal Churchnorm: the episcopal church
- Domain
- episcopalchurch.org
Incident
- Discovered
- Apr 28, 2024
- Materiality determined
- Feb 5, 2025
- Notification sent
- Feb 4, 2025
- Affected individuals
- 37
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 40 weeks(283 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.