The Republican Governors Association
bd_e40fa04553cd585a · schema v1 · pii pii-v1
Full breach record for The Republican Governors Association →The Republican Governors Association (RGA) notified the New Hampshire Attorney General of a data breach involving 4 state residents. Threat actors exploited a vulnerability in Microsoft Exchange Server to access RGA's email environment between February and March 2021. While forensic investigators could not confirm what specific data was accessed, the breach notification letter indicates that some residents' names, Social Security numbers, or payment card information may have been accessible. RGA implemented Microsoft patches, offered two years of credit monitoring, and notified the FBI and state regulators.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 1, 2021
Begins
Mar 10, 2021
Discovered
Sep 15, 2021
Filed
vs. sector median
+8 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_19b6e52c5984a7112021-09-15Verified
- Montana State AGbd_d1b4faf7253b34b82021-09-15Candidate
- Massachusetts State AGbd_dd42f77634ba54a52021-09-15Verified
- Maine State AGbd_fa1f241ce4f249052021-09-15Verified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.