HackingData ExfiltratedIDENTITY_BASICOTHERLowContained
CHESAPEAKE BAY MARITIME MUSEUM, INC.
bd_bd6122882e707793 · schema v1 · pii pii-v1
Full breach record for CHESAPEAKE BAY MARITIME MUSEUM, INC. →Chesapeake Bay Maritime Museum, Inc. notified consumers of an unauthorized access incident occurring August 8-9, 2024. The museum's IT systems were accessed by an unauthorized actor who copied files containing names and other variable data. The museum secured its environment, investigated, and is offering credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday17 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 508 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_95889a4552aa6e8eIndiana State AGfiled 2025-12-30Candidate
- bd_17c0f72b06555476Maine State AGfiled 2026-01-05(6d gap)Verified by operator
- bd_ce8cea50b233d3d2Vermont State AGfiled 2026-01-05(6d gap)Verified
- bd_e9629af8d682f7a0New Hampshire State AGfiled 2026-01-05(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-30-chesapeake-bay-maritime-museum-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 30, 2025
- Raw hash
- aedde58cab9d9a017056af9d2ffb56997661cb8a43a940cd41353b69087d770d
Reporting entity
- Name
- CHESAPEAKE BAY MARITIME MUSEUM, INC.norm: chesapeake bay maritime museum
- Domain
- cbmm.org
Victim entity
- Name
- CHESAPEAKE BAY MARITIME MUSEUM, INC.norm: chesapeake bay maritime museum
- Domain
- cbmm.org
Incident
- Discovered
- Aug 9, 2024
- Materiality determined
- —
- Notification sent
- Dec 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICOTHER
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
Compliance
- Time to disclose
- 17 months(508 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.