MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Mississippi Children's Home Society, CARES Center, Inc., Mississippi Children's Home Services, Inc.
bd_a935f72f5c5e202f · schema v1 · pii pii-v1
Full breach record for Mississippi Children's Home Society, CARES Center, Inc., Mississippi Children's Home Services, Inc. →Mississippi Children’s Home Society (dba Canopy Children’s Solutions) notified Vermont AG of a cybersecurity incident discovered April 4, 2023, where an unauthorized actor gained access to network systems and encrypted files. The actor may have accessed and acquired files containing personal information of current and former members. Canopy engaged forensic specialists, notified federal law enforcement and HHS, and is offering 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday43 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-02-01-mississippi-childrens-home-society-cares-center-mississippi-childrens-home-services-dba
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2024
- Raw hash
- 1ba1cb0e0eb976f27028311abf39f2508add33072c3b48d84a553257f6defcc3
Reporting entity
- Name
- Mississippi Children's Home Society, CARES Center, Inc., Mississippi Children's Home Services, Inc.norm: mississippi children s home society cares center inc mississippi children s home
Victim entity
- Name
- Mississippi Children's Home Society, CARES Center, Inc., Mississippi Children's Home Services, Inc.norm: mississippi children s home society cares center inc mississippi children s home
Incident
- Discovered
- Apr 4, 2023
- Materiality determined
- —
- Notification sent
- Feb 2, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying applicable regulators, including the U.S. Department of Health and Human Services
Compliance
- Time to disclose
- 43 weeks(303 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.