MalwareRansomwareRansom DemandedData EncryptedIDENTITY_GOVERNMENTPIIMediumContained
Girl Scouts of the USA
bd_6bb5f992ea674320 · schema v1 · pii pii-v1
Full breach record for Girl Scouts of the USA →Girl Scouts of Connecticut notified individuals of a ransomware incident discovered on October 21, 2021. Unauthorized access occurred around September 30, 2021, potentially exposing Social Security numbers. The organization engaged forensic experts and the FBI, implemented enhanced security safeguards, and offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2022/GirlScoutsofConnecticut.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 26, 2022
- Raw hash
- 42ffcf274fe1e27a1c0225c303673d344b6fb30b903bbab487481307017d5de7
Reporting entity
- Name
- Girl Scouts of the USAnorm: girl scouts of the usa
- Domain
- girlscoutsoc.org
Victim entity
- Name
- Girl Scouts of the USAnorm: girl scouts of the usa
- Domain
- girlscoutsoc.org
Incident
- Discovered
- Oct 21, 2021
- Materiality determined
- —
- Notification sent
- Jan 7, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted the FBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.