HackingStolen CredentialsData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSHEALTH_BASICMediumContained
Pennsylvania State Education Association
bd_ab8d33219fbbcab5 · schema v1 · pii pii-v1
Full breach record for Pennsylvania State Education Association →Pennsylvania State Education Association (PSEA) disclosed a data security incident occurring on or about July 6, 2024. The unauthorized actor accessed files containing personal information including names, SSNs, driver's licenses, financial account numbers, passwords, and health insurance information. PSEA engaged external cybersecurity professionals, notified law enforcement, and provided free credit monitoring and identity restoration services to affected individuals.
Leak gap clock✗ Leak >180d29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 256 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_410f8f4728a91437New Hampshire State AGfiled 2025-03-18(1d gap)Verified
- bd_b6cf1deaa264fa8aMaryland State AGfiled 2025-03-18(1d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-19-pennsylvania-state-education-association-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2025
- Raw hash
- 0720c536b73e847c54aece79cb61e2f11e9a823c167445ff15398907b4caea74
Reporting entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Victim entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Incident
- Discovered
- Feb 18, 2025
- Materiality determined
- —
- Notification sent
- Mar 19, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- Leak >180dVT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.