HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Moses-Weitzman Health System, Inc.
bd_abcbf8032b31cc54 · schema v1 · pii pii-v1
Full breach record for Moses-Weitzman Health System, Inc. →Moses-Weitzman Health System, Inc. notified the Maryland AG of a cybersecurity incident discovered on Jan 2, 2025. A sophisticated criminal actor accessed IT systems, exfiltrating employee data including names, SSNs, and health information. 14 Maryland residents were affected. MWHS engaged forensic investigators, revoked access, notified law enforcement, and offered 24 months of identity protection services.
Maryland clock✓ MD AG ≤30d28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_06c323e4f068c974Maine State AGfiled 2025-01-30Candidate
- bd_5a05001fa8c1ba75New Hampshire State AGfiled 2025-01-30Verified
- bd_b72ef11708d0139aIndiana State AGfiled 2025-01-30Verified
- bd_de0962eda247ff49Vermont State AGfiled 2025-01-30Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376269.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- 938b1b65168a7b9e7040e7a13f97757d756b3602b7860d67cedf73c925283a1b
Reporting entity
- Name
- Moses-Weitzman Health System, Inc.norm: moses weitzman health system
Victim entity
- Name
- Moses-Weitzman Health System, Inc.norm: moses weitzman health system
Incident
- Discovered
- Jan 2, 2025
- Materiality determined
- —
- Notification sent
- Jan 30, 2025
- Affected individuals
- 14
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- MD AG ≤30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.