HackingGovernmentTransportation & LogisticsGovernmentStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIILowContained
Rhode Island Airport Corporation
bd_6f4d2e8b18754a6a · schema v1 · pii pii-v1
Full breach record for Rhode Island Airport Corporation →Rhode Island Airport Corporation (RIAC) detected suspicious activity on two employee email accounts on May 21, 2025. Investigation confirmed unauthorized access to certain employee email accounts between May 14–21, 2025. Personal information of 151 individuals total (1 Maine resident, 124 Rhode Island residents) may have been exposed. RIAC secured accounts, retained cybersecurity specialists, and offered 60 months of Experian IdentityWorks to affected individuals.
Maine clockDiscovered May 21, 2025 → Filed with AG Jul 2, 202542d ⏱ ME AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_aea58ca54fc0d8b0Vermont State AGfiled 2025-11-26(147d gap)Verified
- bd_7f84d9f81be27124New Hampshire State AGfiled 2025-12-01(152d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/b40f92b2-f33d-480c-9ac1-965ea19617bf.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 2, 2025
- Raw hash
- ea16cb5c3010b063d30f4d5a68b4e4d0f54c899114f7922133011ff17de3881e
Reporting entity
- Name
- Rhode Island Airport Corporationnorm: rhode island airport
- Industry
- Other Government Entity
Victim entity
- Name
- Rhode Island Airport Corporationnorm: rhode island airport
- Industry
- Other Government Entity
- Industry
- GovernmentllmTransportation & Logisticsllm
Incident
- Discovered
- May 21, 2025
- Materiality determined
- —
- Notification sent
- Jul 1, 2025
- Affected individuals
- 1
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- ME AG >30d · 42d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 21, 2025→ Filed with AG: Jul 2, 202542d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.