Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Idaho Transportation Department
bd_a99d0114456ac6af · schema v1 · pii pii-v1
Full breach record for Idaho Transportation Department →Idaho Transportation Department reported a cybersecurity incident involving a single email account compromised between Feb 17-19, 2025. Unauthorized access exposed PII (names, addresses, SSNs) of 225 Idaho residents. The department secured the account, notified the Idaho AG, and is offering one year of credit monitoring via Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed225 affectedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/04/ITD-Supplemental.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2025
- Raw hash
- 7db68d90f23151c20a352623c881473fc54c35cdbde83590d080206b5091c6c3
Reporting entity
- Name
- Idaho Transportation Departmentnorm: idaho transportation department
Victim entity
- Name
- Idaho Transportation Departmentnorm: idaho transportation department
Incident
- Discovered
- Feb 17, 2025
- Materiality determined
- —
- Notification sent
- Apr 3, 2025
- Affected individuals
- 225
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- reported to your office on February 25, 2025
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.