HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowResolved
Great Smoky Mountains Association
bd_e47f4e45b6198cf5 · schema v1 · pii pii-v1
Full breach record for Great Smoky Mountains Association →Great Smoky Mountains Association, a non-profit organization, reported a data breach affecting 8 Maine residents. The breach was a result of an external system hacking incident that occurred between May 21, 2021, and December 18, 2021. The breach was discovered on March 17, 2022. The compromised information includes names in combination with financial account numbers or credit/debit card numbers and their security codes. Affected consumers were notified in writing on June 23, 2022. Identity theft protection services were not offered.
Maine clockDiscovered Mar 17, 2022 → Filed with AG Jun 23, 202298d ✗ ME AG >90d14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4e7de66d1c31fad4Montana State AGfiled 2022-06-23Candidate
- bd_f0aa823fbad710b5Washington State AGfiled 2022-06-23Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/398791e7-0134-4d27-81ef-36b00fa9ccea.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2022
- Raw hash
- c3ca8c83fe9facb4d48b0dd2ce9c98bbe86221de975ebf088f4ac0bca8a20be3
Reporting entity
- Name
- Great Smoky Mountains Associationnorm: great smoky mountains
Victim entity
- Name
- Great Smoky Mountains Associationnorm: great smoky mountains
Incident
- Discovered
- Mar 17, 2022
- Materiality determined
- —
- Notification sent
- Jun 23, 2022
- Affected individuals
- 8
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- ME AG >90d · 98dME resident >60d · 98d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 17, 2022→ Filed with AG: Jun 23, 202298d 90 days ME AG >90d Maine Discovered: Mar 17, 2022→ Notified: Jun 23, 202298d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.