Social EngineeringPhishingStolen CredentialsDelayed DiscoveryCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Greater Amsterdam School District
bd_d412db5228fb7909 · schema v1 · pii pii-v1
Full breach record for Greater Amsterdam School District →Greater Amsterdam School District notified consumers of a data breach where an unauthorized actor accessed district email accounts from Nov 2023 to Feb 2024 via phishing. Affected data included names, SSNs, and financial account numbers. The district engaged forensic experts and offered credit monitoring.
Vermont clock✗ VT AG >45 bday18 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_404cab907fdc5158Indiana State AGfiled 2025-08-27Verified
- bd_bb1d6344f2bdccc7Maine State AGfiled 2025-08-28(1d gap)Verified
- bd_aa04d2e514e096b9New Hampshire State AGfiled 2025-09-02(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-27-greater-amsterdam-school-district-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2025
- Raw hash
- 7efa068a8af23755d16f960e1f01fdacaae4d6b6eca6100c3c972d73b5b99d3e
Reporting entity
- Name
- Greater Amsterdam School Districtnorm: greater amsterdam school district
Victim entity
- Name
- Greater Amsterdam School Districtnorm: greater amsterdam school district
Incident
- Discovered
- Feb 28, 2024
- Materiality determined
- Aug 27, 2025
- Notification sent
- Aug 27, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 18 months(546 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.