HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
The Metropolitan Opera Guild, Inc.
bd_b9bc691f94c35222 · schema v1 · pii pii-v1
Full breach record for The Metropolitan Opera Guild, Inc. →The Metropolitan Opera identified suspicious activity on December 6, 2022. An investigation revealed an unknown actor accessed systems between September 30 and December 6, 2022, and took certain information. The organization secured its network, engaged forensic specialists, notified federal law enforcement, and is offering 12 months of identity monitoring via Kroll. Rhode Island residents are explicitly mentioned as impacted.
Leak gap clock⏱ Leak >30d24 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_22ee330cda5d5334Leak Sitesnatchfiled 2023-03-02(81d gap)Verified by operator
Regulatory filings (6) · sorted by filing gap
- bd_21e3c00dcbe1d3a5Maine State AGfiled 2023-05-22Verified by operator
- bd_1714f3733587599dMaine State AGfiled 2023-05-03(19d gap)Verified by operator
- bd_67aa71088692d379Montana State AGfiled 2023-05-03(19d gap)Verified by operator
- bd_8d10642067442901Oregon State AGfiled 2023-05-03(19d gap)Verified by operator
Show 2 more filings ↓Show fewer ↑up to 19d gap
- bd_8d37d424cf737d37California State AGfiled 2023-05-03(19d gap)Verified
- bd_f97a0a324bb7ac21Vermont State AGfiled 2023-05-03(19d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567098
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2023
- Raw hash
- 29866332847867535040b7d5f626310e441cfb66ca78411640bb564a280223f0
Reporting entity
- Name
- The Metropolitan Opera Guild, Inc.norm: the metropolitan opera guild
Victim entity
- Name
- The Metropolitan Opera Guild, Inc.norm: the metropolitan opera guild
Incident
- Discovered
- Dec 6, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 24 weeks(167 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.