HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
Catholic Charities of the Diocese of Albany
bd_c69e641d8bcc0ecb · schema v1 · pii pii-v1
Full breach record for Catholic Charities of the Diocese of Albany →Catholic Charities of the Diocese of Albany notified consumers of unauthorized network access occurring between March 29 and July 31, 2025. The incident involved access to names and other data elements. The organization reset passwords, conducted an investigation, and offered 12 months of credit monitoring. The specific data types were redacted in the public notice as '<Data Elements>'.
Vermont clock✗ VT AG >45 bday17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by pear about this victim predates this filing by 194 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_98acff8a64d949efNew Hampshire State AGfiled 2025-12-01(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-26-catholic-charities-diocese-albany-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 26, 2025
- Raw hash
- a32aef49ce7560df63a737c70c20cd8a246d3038ad11a3796c373d0256bb3bbf
Reporting entity
- Name
- Catholic Charities of The Archdiocese of Newarknorm: catholic charities of the archdiocese of newark
Victim entity
- Name
- Catholic Charities of the Diocese of Albanynorm: catholic charities of the diocese of albany
- Domain
- ccrcda.org
Incident
- Discovered
- Jul 30, 2025
- Materiality determined
- Nov 24, 2025
- Notification sent
- Nov 24, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.