DisclosureLens
MalwareGovernmentGovernmentRansomwareCapture Stored DataData ExfiltratedTargetedAuthenticationEducationFinancial accountIdentity (basic)Government IDPHIPIIHealth (basic)HighContained

The Seattle Public Library

bd_5ef21f853005bb4b · schema v1 · pii pii-v1

Severity

High

Discovered

May 25, 2024

Filed

Dec 12, 2024

To disclose

29 weeks

Affected

26,965state residents only

Confidence

71%
Full breach record for The Seattle Public Library

The Seattle Public Library experienced a ransomware attack on May 24-25, 2024. The unauthorized actor downloaded files containing personal information (PII) from the Library's network. The Library engaged forensic investigators, notified law enforcement, and implemented MFA and stronger password practices. 26,965 Washington residents were affected. Notices were sent on December 12, 2024.

Washington clock WA AG >90d29 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 1 days
discovery → filing · 29 weeks / 201 days

May 24, 2024

Begins

May 25, 2024

Discovered

Dec 12, 2024

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed26,965 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.