MalwareRansomwareRansom DemandedTargetedPIIIDENTITY_BASICLowContained
Wayne Memorial Hospital
bd_e1539c0ea8da5574 · schema v1 · pii pii-v1
Full breach record for Wayne Memorial Hospital →Wayne Memorial Hospital experienced a ransomware event detected on June 3, 2024. An unauthorized actor accessed the network between May 30 and June 3, 2024, encrypted data, and left a ransom note. The hospital restored systems from backups, engaged forensic investigators, and offered credit monitoring. The primary motive was extortion. No evidence of identity theft was found.
Vermont clock✗ VT AG >45 bday15 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by monti about this victim predates this filing by 461 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4b1cd5f26ef29daaMaine State AGfiled 2025-09-07Candidate
- bd_fb6dd2f52bc66a39Montana State AGfiled 2025-09-07Verified
- bd_4a3a5b5a92d6120fNew Hampshire State AGfiled 2025-09-08(1d gap)Verified
- bd_5c0d27e2856b3300Texas State AGfiled 2025-09-09(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-07-wayne-memorial-hospital-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 7, 2025
- Raw hash
- 8912e963bdbb4c8291f742a2c51b51be43ea62d0b459f0deffa5c9a8bf1c619c
Reporting entity
- Name
- Wayne Memorial Hospitalnorm: wayne memorial hospital
- Domain
- wmh.org
Victim entity
- Name
- Wayne Memorial Hospitalnorm: wayne memorial hospital
- Domain
- wmh.org
Incident
- Discovered
- Jun 3, 2024
- Materiality determined
- —
- Notification sent
- Aug 27, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 months(461 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.