HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPIILowContained
Crystal Lake Elementary District 47
bd_8388bd537c9ccde4 · schema v1 · pii pii-v1
Full breach record for Crystal Lake Elementary District 47 →Crystal Lake Elementary District 47 notified consumers of a cybersecurity incident discovered on October 17, 2024, involving unauthorized access to district systems. Potentially affected data included names and consolidated PII/PHI. The District engaged third-party investigators, secured the network, and offered credit monitoring services. No evidence of actual misuse was found at the time of notification.
Vermont clock✗ VT AG >45 bday16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2fe5712565837316Indiana State AGfiled 2025-02-06Verified
- bd_59a4feedffd39eb8New Hampshire State AGfiled 2025-02-06Verified
- bd_6edc874ad491315aMaine State AGfiled 2025-02-06Candidate
- bd_b1e1fdcfda4806e2Montana State AGfiled 2025-02-06Candidate
Show 1 more filing ↓Show fewer ↑
- bd_d7286d69cd0d7edbMaryland State AGfiled 2025-02-06Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-02-06-crystal-lake-elementary-district-47-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2025
- Raw hash
- f33daa124b7cf876bad53dcc7713671103f5a9b3e7e340bd1f8280cc8f59dde9
Reporting entity
- Name
- Crystal Lake Elementary District 47norm: crystal lake elementary district 47
Victim entity
- Name
- Crystal Lake Elementary District 47norm: crystal lake elementary district 47
Incident
- Discovered
- Oct 17, 2024
- Materiality determined
- —
- Notification sent
- Feb 6, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.