Sandy Spring Museum
bd_5ffa7d1209834eba · schema v1 · pii pii-v1
Full breach record for Sandy Spring Museum →2 incidents on fileSandy Spring Museum notified Maryland AG of a data security incident discovered Jan 16, 2025. An unauthorized individual gained access to systems. Affected data included names, addresses, DOBs, and SSNs of 23 Maryland residents. Museum engaged forensic experts, reset passwords, reformatted desktops, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 16, 2025
Discovered
Feb 3, 2025
Filed
vs. sector median
6 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Vermont State AGbd_f05da4c09585db8c2025-03-03 · +28dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Feb 3 (MD), last Mar 3 (VT) — a 28-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.