HackingIDENTITY_BASICLowContained
The Episcopal Church
bd_c6d052c680ceb727 · schema v1 · pii pii-v1
Full breach record for The Episcopal Church →The Episcopal Church notified consumers of unauthorized network access occurring between March 25 and April 27, 2024. The incident involved access to names and other data elements. The Church changed passwords, reviewed policies, and offered 12 months of credit monitoring and identity protection services via Cyberscout/TransUnion. No evidence of misuse was found.
Vermont clock✗ VT AG >45 bday40 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5bcee5fc74437a1bMaryland State AGfiled 2025-02-05Verified
- bd_605e266749a7eba7Maine State AGfiled 2025-02-05Verified
- bd_a20b51c2f9d250b9New Hampshire State AGfiled 2025-02-05Verified
- bd_e7da2d90ee039989Indiana State AGfiled 2025-02-04(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_d3a899306503e170Montana State AGfiled 2025-02-21(16d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-02-05-episcopal-church-domestic-and-foreign-missionary-society-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2025
- Raw hash
- c165417408dd44f38744a12f9f96c88a0fbfa6540caf48da2c8115277ff2810e
Reporting entity
- Name
- The Episcopal Churchnorm: the episcopal church
- Domain
- episcopalchurch.org
Victim entity
- Name
- The Episcopal Churchnorm: the episcopal church
- Domain
- episcopalchurch.org
Incident
- Discovered
- Apr 28, 2024
- Materiality determined
- Feb 5, 2025
- Notification sent
- Feb 4, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 40 weeks(283 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.