MalwareGovernmentGovernmentRansomwareCapture Stored DataRansom DemandedData ExfiltratedData EncryptedCustomer Data InvolvedTargetedPIILowContained
Union County, Oregon
bd_e13fd488600b1f81 · schema v1 · pii pii-v1
Full breach record for Union County, Oregon →Union County, Ohio detected ransomware on its computer network on May 18, 2025. Threat actors accessed the network from May 6 through May 18, 2025, and exfiltrated County data. A data review was completed on August 25, 2025. A total of 45,487 individuals were affected, including 2 Maine residents. Experian credit monitoring and identity restoration services were offered for 12 months. Federal law enforcement was notified.
Maine clockDiscovered May 18, 2025 → Filed with AG Sep 24, 2025129d ✗ ME AG >90d18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2902fd2c45650c27Montana State AGfiled 2025-09-24Candidate
- bd_c253643f9c1cb792New Hampshire State AGfiled 2025-10-06(12d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/f7a9a409-190a-4ab4-b1df-cafd3eafefe0.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 24, 2025
- Raw hash
- a75e5668b116e79da602af4af6816b65b6a9f8fbfdcd341e74d1dfea5b5be060
Reporting entity
- Name
- Union County, Oregonnorm: union county oregon
- Industry
- Government
Victim entity
- Name
- Union County, Oregonnorm: union county oregon
- Industry
- Government
- Industry
- Governmentllm
Incident
- Discovered
- May 18, 2025
- Materiality determined
- Aug 25, 2025
- Notification sent
- Sep 24, 2025
- Affected individuals
- 2
- Data types
- PII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Alerted federal law enforcementNotifying all appropriate state regulators
Compliance
- Time to disclose
- 18 weeks(129 days from discovery to filing)
- Compliance flags
- ME AG >90d · 129dME resident >60d · 129d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 18, 2025→ Filed with AG: Sep 24, 2025129d 90 days ME AG >90d Maine Discovered: May 18, 2025→ Notified: Sep 24, 2025129d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.