HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Catholic Charities of the Diocese of Rockville Centre
bd_a4ce6d5557f1ecb2 · schema v1 · pii pii-v1
Full breach record for Catholic Charities of the Diocese of Rockville Centre →Catholic Charities of Long Island reported an external system breach (hacking) on September 3, 2023, affecting 20,795 individuals. The incident compromised names and financial account numbers (including credit/debit card numbers with security codes/PINs). The organization notified affected individuals in writing on November 14, 2023, and provided 12 months of credit monitoring and identity theft restoration services via CyberScout. Four Maine residents were specifically affected.
Maine clockDiscovered Sep 3, 2023 → Filed with AG Nov 16, 202374d ⏱ ME AG >30d11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_f7700ca58694302bMontana State AGfiled 2023-11-15(1d gap)Candidate
- bd_0da38bc84853e9cfVermont State AGfiled 2023-11-14(2d gap)Verified
- bd_9692e7d8d8bad845New Hampshire State AGfiled 2023-11-27(11d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1c798ff3-9ea3-4857-bee9-e97633671992.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 16, 2023
- Raw hash
- 2c018027b267be09a366a2c0ed9816cc09c1c981be020febd55628178810abba
Reporting entity
- Name
- Catholic Charities of the Diocese of Rockville Centrenorm: catholic charities of the diocese of rockville centre
Victim entity
- Name
- Catholic Charities of the Diocese of Rockville Centrenorm: catholic charities of the diocese of rockville centre
Incident
- Discovered
- Sep 3, 2023
- Materiality determined
- —
- Notification sent
- Nov 14, 2023
- Affected individuals
- 20,795
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with the Maine Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- ME AG >30d · 74dME resident >60d · 72d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 3, 2023→ Filed with AG: Nov 16, 202374d 30 days (soft) ME AG >30d Maine Discovered: Sep 3, 2023→ Notified: Nov 14, 202372d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.