HackingStolen CredentialsTargetedIDENTITY_BASICCREDENTIALSLowContained
North Carolina Board of Cosmetic Art Examiners
bd_7157d0b87aafe27b · schema v1 · pii pii-v1
Full breach record for North Carolina Board of Cosmetic Art Examiners →The North Carolina Board of Cosmetic Art Examiners notified consumers of a data breach where an unauthorized individual accessed email accounts between Oct 31 and Nov 27, 2024. Affected data included names and other personal information. The Board offered 12-24 months of credit monitoring. Approximately 2 Rhode Island residents were impacted.
Vermont clock✗ VT AG >45 bday32 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6e861a1c943467afIndiana State AGfiled 2025-07-08(1d gap)Verified
- bd_bf66e8a2a2c76dbfNew Hampshire State AGfiled 2025-07-08(1d gap)Verified
- bd_e5387780961f5760Maine State AGfiled 2025-07-08(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-07-north-carolina-board-cosmetic-art-examiners-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2025
- Raw hash
- 95a2c8433e6e9dc85054f03f2d6a6b79563bbd7017cb971e54986534e67519d6
Reporting entity
- Name
- North Carolina Board of Cosmetic Art Examinersnorm: north carolina board of cosmetic art examiners
Victim entity
- Name
- North Carolina Board of Cosmetic Art Examinersnorm: north carolina board of cosmetic art examiners
Incident
- Discovered
- Nov 27, 2024
- Materiality determined
- Jun 17, 2025
- Notification sent
- Jul 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 32 weeks(222 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.