Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Rhode Island Airport Corporation
bd_aea58ca54fc0d8b0 · schema v1 · pii pii-v1
Full breach record for Rhode Island Airport Corporation →Rhode Island Airport Corporation (RIAC) notified consumers of a data breach involving unauthorized access to employee email accounts between May 14 and May 21, 2025. The incident, detected on May 21, 2025, exposed personal information including names, driver's license numbers, SSNs, and medical/health insurance data. Approximately 2,307 individuals were potentially impacted, including 962 Rhode Island residents. RIAC secured accounts, engaged forensic investigators, and is offering 60 months of credit monitoring.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7f84d9f81be27124New Hampshire State AGfiled 2025-12-01(5d gap)Verified
- bd_6f4d2e8b18754a6aMaine State AGfiled 2025-07-02(147d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-26-rhode-island-airport-corporation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 26, 2025
- Raw hash
- f9385c5e075b905a22bbcc633a52fa309411cd26ab59241c24aceadf251acf37
Reporting entity
- Name
- Rhode Island Airport Corporationnorm: rhode island airport
Victim entity
- Name
- Rhode Island Airport Corporationnorm: rhode island airport
Incident
- Discovered
- May 21, 2025
- Materiality determined
- —
- Notification sent
- Nov 25, 2025
- Affected individuals
- 2,307
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.