HackingSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICMediumContained
Gladstone School District
bd_c8fef0812fb79e04 · schema v1 · pii pii-v1
Full breach record for Gladstone School District →Gladstone School District notified the Maryland Attorney General of a data security incident involving its third-party administrator, Carruth Compliance Consulting. The incident, occurring on or about December 21, 2024, involved unauthorized acquisition of personal information including SSNs, driver's licenses, and financial data. One Maryland resident was identified as affected. Gladstone engaged forensic specialists, notified the FBI, and offered credit monitoring services to affected individuals.
Maryland clock⏱ MD AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ae7225460df3c499New Hampshire State AGfiled 2025-02-28Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376439.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 28, 2025
- Raw hash
- 57eacd11bf006b3733519cf0eb7ff905dee51f00b6cc6bb03e20706a359ff4d3
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Gladstone School Districtnorm: gladstone school district
- Domain
- gladstone.k12.or.us
Incident
- Discovered
- Jan 13, 2025
- Materiality determined
- —
- Notification sent
- Feb 28, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of InvestigationNotified Maryland Attorney General
- Third party
- via Carruth Compliance Consulting
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.