HackingCustomer Data InvolvedEmployee Data InvolvedPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Valley Mountain Regional Center
bd_6ae0c34d4c9b5537 · schema v1 · pii pii-v1
Full breach record for Valley Mountain Regional Center →Valley Mountain Regional Center (VMRC), a non-profit providing services to individuals with developmental disabilities, disclosed a data security incident affecting 7 New Hampshire residents. Unauthorized access to personal and health information occurred on or about July 29, 2023, and was discovered on August 1, 2023. VMRC engaged forensic experts, reported the incident to the FBI, and notified residents on April 19, 2024, offering credit monitoring and identity theft recovery services via Cyberscout.
Leak gap clock✗ Leak >180d37 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
A leak claim by karakurt about this victim predates this filing by 232 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5c08fd6ae8156959Indiana State AGfiled 2024-04-19Verified
- bd_62be608eb7747666Oregon State AGfiled 2024-04-19Candidate
- bd_828e5ed96afbae42Montana State AGfiled 2024-04-19Verified by operator
- bd_953affa4774a50d7Vermont State AGfiled 2024-04-19Verified
Show 1 more filing ↓Show fewer ↑
- bd_dfd449502298c885California State AGfiled 2024-04-19Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/valley-mountain-regional-center-20240419.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 19, 2024
- Raw hash
- 409a28608c71b7aa26efeed19d0bfb76e2e3cf54c8aeee116f4b0ed63dede792
Reporting entity
- Name
- Valley Mountain Regional Centernorm: valley mountain regional center
- Domain
- vmrc.net
Victim entity
- Name
- Valley Mountain Regional Centernorm: valley mountain regional center
- Domain
- vmrc.net
Incident
- Discovered
- Aug 1, 2023
- Materiality determined
- —
- Notification sent
- Apr 19, 2024
- Affected individuals
- 7
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 37 weeks(262 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.