Social EngineeringPhishingMisdeliveryCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Darlington County School District
bd_81630a45206a32a0 · schema v1 · pii pii-v1
Full breach record for Darlington County School District →Darlington County School District notified employees that W-2 forms were inadvertently sent to an unauthorized recipient following a communication appearing to be a legitimate internal request (likely phishing). The incident was discovered on April 11, 2026. Affected data includes names and W-2 financial information. DCSD notified law enforcement and the IRS, and is offering 12 months of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_600d0f8d8225bde9Indiana State AGfiled 2026-05-06(1d gap)Verified
- bd_6f365961b92f36dbNew Hampshire State AGfiled 2026-05-06(1d gap)Verified
- bd_79440e54f1985039Massachusetts State AGfiled 2026-05-01(6d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/Consumer%20Letter%20-%20Darlington%20County%20School%20District.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 7, 2026
- Raw hash
- a50ba5b8044b92d052fd5156fbe9486a5e05a24348ec165e7644a4b3cf54169a
Reporting entity
- Name
- Darlington County School Districtnorm: darlington county school district
- Domain
- dcsdschools.org
Victim entity
- Name
- Darlington County School Districtnorm: darlington county school district
- Domain
- dcsdschools.org
Incident
- Discovered
- Apr 11, 2026
- Materiality determined
- —
- Notification sent
- May 6, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcementNotified the Internal Revenue Service (IRS)
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.