HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Aya Healthcare
bd_a9f3734972f43502 · schema v1 · pii pii-v1
Full breach record for Aya Healthcare →Aya Healthcare, Inc. notified consumers of a data security incident where unauthorized third parties used stolen credentials (usernames/passwords from unrelated sources) to gain access to user accounts. The breach occurred on January 12 and 19, 2025. An automated bot accessed limited information including names, contact info, nursing license numbers, SSNs, and vaccination status. Aya engaged cybersecurity experts, reset passwords, and offered 24 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_004fdddbe9969934Indiana State AGfiled 2025-02-27Verified
- bd_1e9f96661e12cc26Montana State AGfiled 2025-02-27Candidate
- bd_1feaf1979c4f4091Maryland State AGfiled 2025-02-27Verified
- bd_514b32eabd91432cMaine State AGfiled 2025-02-27Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-02-27-aya-healthcare-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2025
- Raw hash
- 5bcd5b8cd76698e47afbc7361d8976c68bab12059d873ae901ea497bb26032e4
Reporting entity
- Name
- Aya Healthcarenorm: aya healthcare
- Domain
- ayahealthcare.com
Victim entity
- Name
- Aya Healthcarenorm: aya healthcare
- Domain
- ayahealthcare.com
Incident
- Discovered
- Jan 12, 2025
- Materiality determined
- —
- Notification sent
- Feb 27, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.