HackingData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Missouri Botanical Garden
bd_91a045e715c9b7b9 · schema v1 · pii pii-v1
Full breach record for Missouri Botanical Garden →Missouri Botanical Garden notified consumers of a data security incident occurring on or around March 7, 2024, where an unauthorized third party accessed the network and acquired files containing PII, including SSNs, driver's licenses, passport numbers, and medical/health insurance information. The investigation concluded August 26, 2024. The Garden engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring and fraud assistance. A specific count of 7 Rhode Island residents was noted in the attached notice.
Vermont clock✗ VT AG >45 bday28 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_52038c563d169012Indiana State AGfiled 2024-09-19Verified
- bd_90beed8d5a6545c9Montana State AGfiled 2024-09-23(4d gap)Candidate
- bd_b3e7d5b1ea07b21cNew Hampshire State AGfiled 2024-09-23(4d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-19-missouri-botanical-garden-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 19, 2024
- Raw hash
- d0cf08f2ffda5629dd20673b9fadef4cc9be1fd7fff1a9dbaa940387557996fa
Reporting entity
- Name
- Missouri Botanical Gardennorm: missouri botanical garden
Victim entity
- Name
- Missouri Botanical Gardennorm: missouri botanical garden
Incident
- Discovered
- Mar 7, 2024
- Materiality determined
- —
- Notification sent
- Sep 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported this to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 weeks(196 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.