MalwareHealthcareHealthcareRansomwareCapture Stored DataBlack BastaRansom DemandedData ExfiltratedData EncryptedData PublishedData Leak ThreatenedActor NamedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumResolved
WorldOne Inc.
bd_7c49c9b0c9b49ab6 · schema v1 · pii pii-v1
Full breach record for WorldOne Inc. →WorldOne Inc. dba Sermo suffered a Black Basta ransomware attack. Unauthorized access to Sermo's network occurred March 19–April 10, 2024. Black Basta posted exfiltrated data on its leak site April 17, 2024. SSNs of 5 Maine residents were identified after a lengthy data review. Individuals notified February 9, 2026; 12 months of Kroll identity monitoring offered.
Maine clockDiscovered Apr 10, 2024 → Filed with AG Feb 9, 2026670d ✗ ME AG >90d22 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2c692d17ae0811bdIndiana State AGfiled 2026-02-09Candidate
- bd_8b6e47cbe8564c3eNew Hampshire State AGBlack Bastafiled 2026-02-09Verified
- bd_f9e4422ef61e72aeIndiana State AGfiled 2026-02-09Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/b2392c26-fd7b-437c-b13d-eef3668b5aec.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 9, 2026
- Raw hash
- 2795d2b187c10a719cf31bddf59d0e2edba8720e4b3eae19583e7ff4f84336f2
Reporting entity
- Name
- WorldOne Inc.norm: worldone
- Domain
- sermo.com
- Industry
- Healthcare professional knowledge platform
Victim entity
- Name
- WorldOne Inc.norm: worldone
- Domain
- sermo.com
- Industry
- Healthcare professional knowledge platform
- Industry
- Healthcarellm
Incident
- Discovered
- Apr 10, 2024
- Materiality determined
- —
- Notification sent
- Feb 9, 2026
- Affected individuals
- 5
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Ransomware· Black Basta
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- Black BastaExternalFinancial
Compliance
- Time to disclose
- 22 months(670 days from discovery to filing)
- Compliance flags
- ME AG >90d · 670dME resident >180d · 670d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 10, 2024→ Filed with AG: Feb 9, 2026670d 90 days ME AG >90d Maine Discovered: Apr 10, 2024→ Notified: Feb 9, 2026670d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.