HackingTargetedIDENTITY_BASICLowContained
Ohio Lottery
bd_890fd36e2b242c06 · schema v1 · pii pii-v1
Full breach record for Ohio Lottery →Ohio Lottery notified consumers of a cybersecurity incident detected on Dec 24, 2023, involving unauthorized access to its internal office network. The breach exposed full names. The Lottery engaged external forensic investigators and is offering free credit monitoring. No evidence of misuse was found.
Vermont clock✗ VT AG >45 bday19 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 139 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_2be9a6f3432fb095Leak Sitedragonforcefiled 2023-12-27(132d gap)Verified
- bd_e611336358a91bcaLeak Sitedragonforcefiled 2023-12-21(139d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_6786e9304a70c4daIndiana State AGfiled 2024-05-08Candidate
- bd_bd2c8759df7fbb5bCalifornia State AGfiled 2024-05-09(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-08-ohio-lottery-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2024
- Raw hash
- 60a533f30660e7263a1c51c946a4c0cc3f42ddacc45a6faa7f472b3ce293c453
Reporting entity
- Name
- Ohio Lotterynorm: ohio lottery
- Domain
- ohiolottery.com
Victim entity
- Name
- Ohio Lotterynorm: ohio lottery
- Domain
- ohiolottery.com
Incident
- Discovered
- Dec 24, 2023
- Materiality determined
- May 8, 2024
- Notification sent
- May 8, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(136 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.