MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Texas Tech University Health Sciences Center
bd_6c61d54a8c64be66 · schema v1 · pii pii-v1
Full breach record for Texas Tech University Health Sciences Center →Texas Tech University Health Sciences Center notified the Maryland Attorney General of a cybersecurity event occurring between September 17 and 29, 2024. The incident involved unauthorized access to systems, resulting in the encryption of files and potential exfiltration of data. Approximately 145 Maryland residents were affected, with impacted data including names, driver's license numbers, SSNs, financial account information, and medical records. TTUHSC engaged third-party specialists, notified law enforcement, and provided 12 months of credit monitoring.
Leak gap clock✗ Leak >180d14 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed145 affectedView incident
A leak claim by interlock about this victim predates this filing by 381 days.View originating leak claim
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376243.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 3816d296f6a877865446aee56a4b7df56c6278a28244e4bb079b18f04b91e7b6
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Texas Tech University Health Sciences Centernorm: texas tech university health sciences center
- Domain
- ttuhsc.edu
Incident
- Discovered
- Sep 29, 2024
- Materiality determined
- —
- Notification sent
- Nov 25, 2024
- Affected individuals
- 145
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 months(410 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.