MalwareRansomwareData ExfiltratedTargetedPIIIDENTITY_BASICLowContained
Regional Transportation Authority of Northeastern Illinois
bd_b34e58983fd4ef7a · schema v1 · pii pii-v1
Full breach record for Regional Transportation Authority of Northeastern Illinois →On or about March 4, 2023, the Regional Transportation Authority of Northeastern Illinois (RTA) discovered unauthorized access to its systems by an unknown actor between March 1-3, 2023. The incident involved ransomware activity that rendered systems inaccessible. RTA determined that personal information, including names, was accessed. RTA engaged cyber incident response specialists, notified federal law enforcement, and offered credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday23 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5b4a81b839af1371Maine State AGfiled 2023-08-14Candidate
- bd_64574ce9cefe1641Montana State AGfiled 2023-08-14Verified by operator
- bd_c649b7a19c6ad3b6New Hampshire State AGfiled 2023-08-15(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-14-regional-transportation-authority-northeastern-illinois-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2023
- Raw hash
- f57cf84c93f8605264b4c24266688b1d8948ae595708be33c4fac30859c631e1
Reporting entity
- Name
- Regional Transportation Authority of Northeastern Illinoisnorm: regional transportation authority of northeastern illinois
Victim entity
- Name
- Regional Transportation Authority of Northeastern Illinoisnorm: regional transportation authority of northeastern illinois
Incident
- Discovered
- Mar 4, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported this event to federal law enforcement and government regulators
Compliance
- Time to disclose
- 23 weeks(163 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.