HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Montgomery County Board of Developmental Disabilities Services
bd_7ac005f1b842ed3b · schema v1 · pii pii-v1
Full breach record for Montgomery County Board of Developmental Disabilities Services →Montgomery County Board of Developmental Disabilities Services (MCBDDS) reported a cybersecurity incident discovered on February 20, 2024, involving unauthorized access to its network. The breach potentially exposed sensitive personal information of individuals, including New Hampshire residents. MCBDDS engaged forensic investigators, secured its network, and offered credit monitoring services to affected individuals.
Leak gap clock⏱ Leak >30d16 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
A leak claim by blacksuit about this victim predates this filing by 30 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_627ce800a47f5287Montana State AGfiled 2024-06-10Candidate
- bd_9997e064fec99da8Indiana State AGfiled 2024-06-10Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/montgomery-county-board-developmental-disabilities-20240610.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2024
- Raw hash
- b2166e7b743678b352c5d4b3a09a15cef64d2b45a2914072746d76cf7244694c
Reporting entity
- Name
- Montgomery County Board of Developmental Disabilities Servicesnorm: montgomery county board of developmental disabilities
- Domain
- mcbdds.org
Victim entity
- Name
- Montgomery County Board of Developmental Disabilities Servicesnorm: montgomery county board of developmental disabilities
- Domain
- mcbdds.org
Incident
- Discovered
- Feb 20, 2024
- Materiality determined
- May 13, 2024
- Notification sent
- Jun 10, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.