DisclosureLens
HackingTransportationCustomer Data InvolvedIdentity (basic)Government IDHighResolved

Keolis Commuter Services

bd_5cdd081827aae875 · schema v1 · pii pii-v1

Severity

High

Discovered

Oct 10, 2020

Filed

Nov 10, 2020

To disclose

4 weeks

Affected · nationwide

8,74651 in this filing

Linked

3 filings

Confidence

65%
Full breach record for Keolis Commuter Services

Keolis Commuter Services experienced an external system breach on October 10, 2020, which was also discovered on the same day. The incident affected 8,746 individuals, compromising their names and driver's license or non-driver identification card numbers. Written notifications were sent to affected parties on November 10, 2020, and 24 months of identity protection services from Experian were offered.

Maine clockDiscovered Oct 10, 2020Filed with AG Nov 10, 202031d ME AG >30d4 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 4 weeks / 31 days

Oct 10, 2020

Begins

Oct 10, 2020

Discovered

Nov 10, 2020

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Massachusetts State AGNov 10 · first
Maine State AGNov 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.