DisclosureLens
MalwareProfessional ServicesProfessional ServicesRansomwareData ExfiltratedData EncryptedRansom DemandedIdentity (basic)Government IDMediumContained

The County Commissioners Association of Ohio

bd_9967d2c98bc434ff · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 14, 2023

Filed

Feb 23, 2024

To disclose

14 weeks

Affected

3state residents only

Linked

3 filings

Confidence

64%
Full breach record for The County Commissioners Association of Ohio

The County Commissioners Association of Ohio (CCAO) disclosed a ransomware attack on November 14, 2023. Unauthorized access occurred, and cyber criminals removed files containing names and Social Security numbers. CCAO engaged forensic investigators, notified federal law enforcement, and is offering 12 months of Experian identity monitoring. No evidence of data release on the Dark Web was found.

Incident timeline

discovery → filing · 14 weeks / 101 days

Nov 14, 2023

Begins

Nov 14, 2023

Discovered

Feb 23, 2024

Filed

vs. sector median

3 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Indiana State AGDec 29 · first
Montana State AG+56d · this page

Pattern: first filing Dec 29 (IN), last Feb 26 (NH) — a 59-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.