HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSPHIHEALTH_BASICHighContained
Pennsylvania State Education Association
bd_b6cf1deaa264fa8a · schema v1 · pii pii-v1
Full breach record for Pennsylvania State Education Association →Pennsylvania State Education Association (PSEA) notified Maryland AG of a data security incident occurring July 6, 2024, discovered Feb 18, 2025. An unauthorized actor accessed files containing PII, SSNs, financial data, and health info. ~1,203 Maryland residents affected. PSEA engaged forensic investigators, provided substitute notice, and offered credit monitoring.
Leak gap clock✗ Leak >180d28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 255 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_410f8f4728a91437New Hampshire State AGfiled 2025-03-18Verified
- bd_ab8d33219fbbcab5Vermont State AGfiled 2025-03-19(1d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376566.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 18, 2025
- Raw hash
- 000f735fb3b9926a98c7bf9d93d7a92a73dc6ab3062777e0d30406835f91da8f
Reporting entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Victim entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Incident
- Discovered
- Feb 18, 2025
- Materiality determined
- —
- Notification sent
- Mar 17, 2025
- Affected individuals
- 1,203
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- Leak >180dMD AG ≤30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.