MalwareRansomwareData ExfiltratedData PublishedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Douglas County Libraries
bd_a1686723594346df · schema v1 · pii pii-v1
Full breach record for Douglas County Libraries →Douglas County Libraries experienced a ransomware incident in January 2024. Unauthorized actors accessed systems between Jan 13-14, 2024, encrypting data and exfiltrating files containing names and SSNs. Data was subsequently leaked online. The library engaged cybersecurity firms, notified law enforcement, and offered credit monitoring. No specific affected individual count was disclosed.
Vermont clock✗ VT AG >45 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 77 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2653308f1b2f337eMontana State AGfiled 2024-03-20Candidate
- bd_eec61b58efe16616Indiana State AGfiled 2024-03-20Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-03-20-douglas-county-libraries-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2024
- Raw hash
- 1d3a15e225fca520eb8e729153db37ff9822ea1a804c38c4f624deccb43be704
Reporting entity
- Name
- Douglas County Librariesnorm: douglas county libraries
- Domain
- dcl.org
Victim entity
- Name
- Douglas County Librariesnorm: douglas county libraries
- Domain
- dcl.org
Incident
- Discovered
- Jan 14, 2024
- Materiality determined
- —
- Notification sent
- Mar 20, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement and continue to support their investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.