HackingSupply Chain (3P Vendor)PIIIDENTITY_BASICLowContained
The Episcopal Church
bd_5e0ac4f183a6bec1 · schema v1 · pii pii-v1
Full breach record for The Episcopal Church →The Episcopal Church Foundation disclosed a cybersecurity incident involving a third-party IT vendor on February 17, 2025. The incident resulted in unauthorized access to ECF files containing personal information. ECF severed ties with the vendor, engaged external experts, notified law enforcement, and offered 24 months of credit monitoring. No specific count of affected individuals was provided.
Vermont clock✗ VT AG >45 bday23 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_94b5f0476cdd0a6aIndiana State AGfiled 2025-07-28Verified
- bd_e7d214e043ade00aMaine State AGfiled 2025-07-28Candidate
- bd_faa9bfc58c889769New Hampshire State AGfiled 2025-07-30(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-28-episcopal-church-foundation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2025
- Raw hash
- 28f09d9c9cc7ab6f168ad5fed7f12a58e367ca8ffb7b9a80ea4a4e5bc6f60a05
Reporting entity
- Name
- The Episcopal Churchnorm: the episcopal church
- Domain
- episcopalchurch.org
Victim entity
- Name
- The Episcopal Churchnorm: the episcopal church
- Domain
- episcopalchurch.org
Incident
- Discovered
- Feb 17, 2025
- Materiality determined
- —
- Notification sent
- Jul 28, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Notified law enforcement
- Third party
- via third-party IT vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 23 weeks(161 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.