HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedCREDENTIALSPIILowContained
Public Allies
bd_8b0978b5a47a8790 · schema v1 · pii pii-v1
Full breach record for Public Allies →Public Allies, Inc. notified individuals that on or about December 17, 2020, a database containing employee and applicant usernames and passwords was found on the internet as part of a larger data leak from other organizations. Public Allies found no unauthorized access to its own systems but conducted a manual review to identify impacted individuals. The notice covers residents in Delaware, DC, Maryland, Rhode Island, and New York.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_2c7028d468b8dc5bCalifornia State AGfiled 2021-06-07Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/06/Public-Allies-Inc.-DE-Notice-of-Data-Event.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 7, 2021
- Raw hash
- 6e51b913db82f5edbcb8dd66692b972d46b4e10c650913699f76d7b5c6f96974
Reporting entity
- Name
- Public Alliesnorm: public allies
- Domain
- publicallies.org
Victim entity
- Name
- Public Alliesnorm: public allies
- Domain
- publicallies.org
Incident
- Discovered
- Dec 17, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(172 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.