HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICCREDENTIALSMediumContained
Pennsylvania State Education Association
bd_e3037620ed0e1d3f · schema v1 · pii pii-v1
Full breach record for Pennsylvania State Education Association →Pennsylvania State Education Association (PSEA) disclosed a data security incident occurring on or about July 6, 2024. An unauthorized actor accessed PSEA's network and acquired personal information, including names combined with SSNs, driver's licenses, financial account numbers, PINs, passwords, and health insurance information. PSEA engaged external cybersecurity professionals, notified law enforcement, and ensured the unauthorized actor deleted the data. Affected individuals were offered free credit monitoring and identity restoration services through IDX.
Leak gap clock✗ Leak >180d36 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 255 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_76c28a981abcc69aLeak Siterhysidafiled 2024-09-09(189d gap)Verified by operator
- bd_9ec6a1b78fc5745eLeak Siterhysidafiled 2024-07-06(255d gap)Candidate
Regulatory filings (3) · sorted by filing gap
- bd_18c2400cad54db48Maine State AGfiled 2025-03-18Verified by operator
- bd_4eadf3bce2328f76Washington State AGfiled 2025-03-18Candidate
- bd_8b3ad0c34719e966Montana State AGfiled 2025-03-18Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2025/03/Pennsylvania_State_Education_Association_-_Website_Substitute_Notice_35887682v1.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 18, 2025
- Raw hash
- 506f3d00db58680afaab2fb4a2ff2e5d9cdcdcd7dcf2a2ef46e71a2880047d5d
Reporting entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Victim entity
- Name
- Pennsylvania State Education Associationnorm: pennsylvania state education
- Domain
- psea.org
Incident
- Discovered
- Jul 6, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 36 weeks(255 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.