HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
Town of Stowe
bd_ce526447f985e0b5 · schema v1 · pii pii-v1
Full breach record for Town of Stowe →Town of Stowe, Vermont notified New Hampshire AG of unauthorized access to five email accounts from Aug 29 to Sep 7, 2022. Suspicious activity detected Aug 30, 2022. Data potentially exposed included names, DOB, SSN, driver's license, passport, financial account numbers, and medical/insurance info for 8 NH residents. Notices sent Feb 14, 2023 with credit monitoring offers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_2e23576febac91afMaine State AGfiled 2023-02-14Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/stowe-vermont-20230214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2023
- Raw hash
- f78d39afeb687b05d681982847bc576ffc297f3d7a2db6968b9208ebc2b64e54
Reporting entity
- Name
- Town of Stowenorm: town of stowe
Victim entity
- Name
- Town of Stowenorm: town of stowe
Incident
- Discovered
- Aug 30, 2022
- Materiality determined
- Dec 15, 2022
- Notification sent
- Feb 14, 2023
- Affected individuals
- 8
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified the Office of the Attorney General of the State of New Hampshire
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 weeks(168 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.