HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
TST BOCES
bd_99e7bdebaef18e4d · schema v1 · pii pii-v1
Full breach record for TST BOCES →TST BOCES notified consumers of a data security incident where an unauthorized person accessed systems containing personal information, including Social Security numbers and financial account data for direct deposit. The incident was discovered on April 2, 2023. TST BOCES engaged a third-party cybersecurity firm, secured systems, and offered one year of complimentary credit monitoring via TransUnion.
Vermont clock✗ VT AG >45 bday10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_9c96f50bb988e2a6Maine State AGfiled 2023-06-09Candidate
- bd_fd4aae4bea631ff4Montana State AGfiled 2023-06-09Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-09-tst-boces-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 9, 2023
- Raw hash
- dd85224b2fcb6a48bbabd44f35277710e5bfd03813ca042e43e9c71d073b1529
Reporting entity
- Name
- TST BOCESnorm: tst boces
Victim entity
- Name
- TST BOCESnorm: tst boces
Incident
- Discovered
- Apr 2, 2023
- Materiality determined
- —
- Notification sent
- Jun 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.