HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
McHenry County Conservation District
bd_675a31e55e5b0165 · schema v1 · pii pii-v1
Full breach record for McHenry County Conservation District →McHenry County Conservation District notified consumers that an unauthorized third party accessed a single employee email account between May 15 and May 30, 2023. The attacker viewed personal information including names and addresses. The district secured the account, engaged forensic investigators, and offered one year of Experian IdentityWorks credit monitoring.
Vermont clock✗ VT AG >45 bday13 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-28-mchenry-county-conservation-district-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2023
- Raw hash
- caeb8f9864dbf6640affdbc7e3d2eb18816eea0ebc3ccce347cb84d184209dcd
Reporting entity
- Name
- McHenry County Conservation Districtnorm: mchenry county conservation district
Victim entity
- Name
- McHenry County Conservation Districtnorm: mchenry county conservation district
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Aug 28, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.