HackingStolen CredentialsData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Institute of Culinary Education
bd_76c86c55a1736a8e · schema v1 · pii pii-v1
Full breach record for Institute of Culinary Education →The Institute of Culinary Education notified consumers of a data breach occurring around May 5, 2025, where an unauthorized actor accessed systems and copied files containing names and government IDs. The Institute investigated, implemented additional cybersecurity measures, and is offering 12-24 months of credit monitoring and identity theft protection through Epiq.
Vermont clock✗ VT AG >45 bday22 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by payoutsking about this victim predates this filing by 131 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2a7d823e75938fd3New Hampshire State AGfiled 2025-10-06Verified
- bd_4c07637677e4b748Indiana State AGfiled 2025-10-06Verified
- bd_de4f194ba8ae1486Montana State AGfiled 2025-10-06Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-06-institute-culinary-education-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2025
- Raw hash
- e187a4c7603933afc3900cb24c2cc7b27a39735819971775e7bb887fb96b2f86
Reporting entity
- Name
- Institute of Culinary Educationnorm: institute of culinary education
- Domain
- ice.edu
Victim entity
- Name
- Institute of Culinary Educationnorm: institute of culinary education
- Domain
- ice.edu
Incident
- Discovered
- May 5, 2025
- Materiality determined
- —
- Notification sent
- Oct 6, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(154 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.