HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPIIMediumContained
Crystal Lake Elementary District 47
bd_d7286d69cd0d7edb · schema v1 · pii pii-v1
Full breach record for Crystal Lake Elementary District 47 →Crystal Lake Elementary District 47 notified the Maryland AG of a data incident affecting 9 Maryland residents. Unauthorized access occurred on Oct 17, 2024, exposing names, SSNs, education, and health info. The district secured the network, engaged investigators, notified law enforcement, and offered credit monitoring.
Maryland clock✗ MD AG >90d16 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2fe5712565837316Indiana State AGfiled 2025-02-06Verified
- bd_59a4feedffd39eb8New Hampshire State AGfiled 2025-02-06Verified
- bd_6edc874ad491315aMaine State AGfiled 2025-02-06Candidate
- bd_8388bd537c9ccde4Vermont State AGfiled 2025-02-06Verified
Show 1 more filing ↓Show fewer ↑
- bd_b1e1fdcfda4806e2Montana State AGfiled 2025-02-06Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376330.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2025
- Raw hash
- 895f1adef2e3727c03ef7612a1dac1d1e5a73ad64bead598e6fe53b4a16a6561
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- Crystal Lake Elementary District 47norm: crystal lake elementary district 47
Incident
- Discovered
- Oct 17, 2024
- Materiality determined
- Feb 6, 2025
- Notification sent
- Feb 6, 2025
- Affected individuals
- 9
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maryland Attorney General
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.