HackingStolen CredentialsCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
American Association of Critical-Care Nurses
bd_db08057b57a2eded · schema v1 · pii pii-v1
Full breach record for American Association of Critical-Care Nurses →American Association of Critical-Care Nurses (AACN) notified consumers of a data security incident involving its website's payment system. An unauthorized party accessed payment card information (card number, expiry, CVV), names, and contact details for transactions occurring between March 8, 2025, and July 31, 2025. AACN engaged outside security experts, secured the system, and is offering two years of complimentary credit and identity monitoring.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_8242bb219dadeba0Texas State AGfiled 2025-09-04(2d gap)Verified
- bd_475370cbda26655dCalifornia State AGfiled 2025-08-29(4d gap)Candidate
- bd_6820d7d37f0ea9fdOregon State AGfiled 2025-08-29(4d gap)Verified
- bd_80f7a1e26b0cb573Indiana State AGfiled 2025-08-29(4d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 4d gap
- bd_d266e08df4700389Montana State AGfiled 2025-08-29(4d gap)Verified
- bd_d512ba3bd7ec0b45New Hampshire State AGfiled 2025-08-29(4d gap)Verified
- bd_e05bd527f050d997Maine State AGfiled 2025-08-29(4d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-02-american-association-critical-care-nurses-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 2, 2025
- Raw hash
- 63446c4fc16eb06254247c87291186d1f385bb47f0ab3fe20b762d94bd3a34ff
Reporting entity
- Name
- American Association of Critical-Care Nursesnorm: american association of critical care nurses
- Domain
- aacn.org
Victim entity
- Name
- American Association of Critical-Care Nursesnorm: american association of critical care nurses
- Domain
- aacn.org
Incident
- Discovered
- Jul 31, 2025
- Materiality determined
- Sep 2, 2025
- Notification sent
- Aug 29, 2025
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.