Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Toledo Public Schools
bd_63ebda663911d83c · schema v1 · pii pii-v1
Full breach record for Toledo Public Schools →Toledo Public Schools experienced an external system breach (hacking) via email phishing between September 6 and 8, 2020. The incident compromised names and financial account numbers (including credit/debit card numbers with security codes/PINs) for 66,280 individuals, including 3 Maine residents. Notification was sent on December 15, 2020, and 24 months of identity theft protection services were offered.
Maine clockDiscovered Sep 8, 2020 → Filed with AG Dec 15, 202098d ✗ ME AG >90d14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by maze about this victim predates this filing by 98 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_b6a6fa1b7f9ac0ccLeak Sitemazefiled 2020-09-08(98d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_169eb168e655af89Maine State AGfiled 2020-12-15Verified
- bd_b59972043481565bMontana State AGfiled 2020-12-14(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/140ccc91-c0c8-4f2a-9aa2-9edb13671939.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2020
- Raw hash
- 1a64c66be78171913dd47f1713bd14656d2334a63a440abfc9da5aabc602da1e
Reporting entity
- Name
- Toledo Public Schoolsnorm: toledo public schools
Victim entity
- Name
- Toledo Public Schoolsnorm: toledo public schools
Incident
- Discovered
- Sep 8, 2020
- Materiality determined
- —
- Notification sent
- Dec 15, 2020
- Affected individuals
- 66,280
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- ME AG >90d · 98dME resident >60d · 98dLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 8, 2020→ Filed with AG: Dec 15, 202098d 90 days ME AG >90d Maine Discovered: Sep 8, 2020→ Notified: Dec 15, 202098d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.