DisclosureLens
HackingOtherStolen CredentialsCustomer Data InvolvedIdentity (basic)PIIMediumContained

Catholic Diocese of Cleveland

bd_8a8733f78e2c4990 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 20, 2025

Filed

Jul 10, 2024

To disclose

Affected · nationwide

10,7541 in this filing

Linked

8 filings

Confidence

66%
Full breach record for Catholic Diocese of Cleveland2 incidents on file

The Catholic Diocese of Cleveland reported an unauthorized access to an employee's business email account occurring between December 14, 2023, and January 12, 2024. The incident was discovered on February 20, 2025, affecting 10,754 individuals whose names and other personal identifiers were potentially acquired. The Diocese engaged third-party forensic investigators, contained the incident, and provided 12 months of credit monitoring to affected individuals.

Incident timeline

undetected · 434 days
discovery → filing · ≤1 day / 0 days

Dec 14, 2023

Begins

Feb 20, 2025

Discovered

Jul 10, 2024

Filed

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 79d gap

Filing propagation · 8 filings · 6 states

View merged incident ↗

Pattern: first filing Apr 22 (MT), last Jul 10 (ME) — a 79-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.