HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Muscogee County School District
bd_ae5dd22ff1e50643 · schema v1 · pii pii-v1
Full breach record for Muscogee County School District →Muscogee County School District (MCSD) notified the New Hampshire Attorney General of a security incident where an unknown third party accessed MCSD's network between December 12 and December 26, 2024. The breach potentially exposed PII, including names and Social Security numbers, of four New Hampshire residents. MCSD secured its network, engaged cybersecurity experts, notified law enforcement, and sent notification letters on August 14, 2025, offering one year of credit monitoring.
Leak gap clock✗ Leak >180d35 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by safepay about this victim predates this filing by 242 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_16d60edf0ce3073fMaine State AGfiled 2025-08-20(5d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/muscogee-county-school-district-20250825.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2025
- Raw hash
- 3b32e436d35faa1cc45abed6033e911b376022b3eba6a82ea59582c20db27b00
Reporting entity
- Name
- Baker, Donelson, Bearman, Caldwell & Berkowitz, A Professional Corporationnorm: baker donelson bearman caldwell berkowitz a
Victim entity
- Name
- Muscogee County School Districtnorm: muscogee county school district
- Domain
- muscogee.k12.ga.us
- Industry
- education
Incident
- Discovered
- Dec 26, 2024
- Materiality determined
- —
- Notification sent
- Aug 14, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 35 weeks(242 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.