HackingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Oklahoma Tax Commission
bd_d4fd04889cc15d7c · schema v1 · pii pii-v1
Full breach record for Oklahoma Tax Commission →The Oklahoma Tax Commission (OTC) disclosed a data breach affecting its OkTAP system. Unauthorized access occurred between September 18, 2025, and December 20, 2025, exposing names and Social Security numbers from W-2 and 1099 files. The OTC notified 10 Vermont residents on March 27, 2026, offering 12 months of credit monitoring. The incident is contained, with additional safeguards implemented.
Vermont clock✗ VT AG >45 bday17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_106ec023e6c2444aMaine State AGfiled 2026-03-27Candidate
- bd_59f67e4c69e02380New Hampshire State AGfiled 2026-03-27Verified
- bd_9761396221115132California State AGfiled 2026-03-27Verified
- bd_c855c9473a93d594Indiana State AGfiled 2026-03-27Verified
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_1009fe78a84233d0Texas State AGfiled 2026-03-30(3d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-27-state-oklahoma-data-breach-notice-consumers-pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2026
- Raw hash
- 89aaed1cc05b72f6354041233691ffc9f12f087adace443b4c5965aa06699ded
Reporting entity
- Name
- SECURITY STATE BANK OF OKLAHOMAnorm: security state bank of oklahoma
Victim entity
- Name
- Oklahoma Tax Commissionnorm: oklahoma tax commission
- Domain
- tax.ok.gov
Incident
- Discovered
- Dec 1, 2025
- Materiality determined
- —
- Notification sent
- Mar 27, 2026
- Affected individuals
- 10
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Providing written notice of this event to relevant state privacy regulatorsProviding written notice to the three (3) major credit reporting agencies: Equifax, Experian, and TransUnion
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.