HackingTargetedIDENTITY_BASICLowContained
Washington Prime Group Inc
bd_ab43fabd68b11973 · schema v1 · pii pii-v1
Full breach record for Washington Prime Group Inc →Washington Prime Group Holdings L.P. notified consumers of a cybersecurity event where an unauthorized third party accessed systems between July 30 and August 9, 2025. The incident may have exposed names and other personal information. WPG secured the network, investigated the scope, and is offering 12 months of credit monitoring and identity restoration services via Experian to affected individuals.
Vermont clock✗ VT AG >45 bday19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by worldleaks about this victim predates this filing by 137 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6bf836bc68e91f42Leak Siteworldleaksfiled 2025-08-08(137d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_5df67242b2b72defMontana State AGfiled 2025-12-23Verified by operator
- bd_f75aec4f7716b5a6Texas State AGfiled 2026-03-09(76d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-23-washington-prime-group-holdings-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2025
- Raw hash
- 9cc480a59274ef5018c2f781985cbebf22b8d781650a7c31700a2901060caf08
Reporting entity
- Name
- Washington Prime Group Incnorm: washington prime
- Domain
- wpgus.com
Victim entity
- Name
- Washington Prime Group Incnorm: washington prime
- Domain
- wpgus.com
Incident
- Discovered
- Aug 11, 2025
- Materiality determined
- Nov 24, 2025
- Notification sent
- Dec 23, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(134 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.