HackingGovernmentGovernmentStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryData ExfiltratedPIIIDENTITY_GOVERNMENTMediumContained
North Carolina Board of Cosmetic Art Examiners
bd_e5387780961f5760 · schema v1 · pii pii-v1
Full breach record for North Carolina Board of Cosmetic Art Examiners →North Carolina Board of Cosmetic Art Examiners (NCBCAE) experienced an unauthorized access to certain email accounts between October 31 and November 27, 2024. Discovered on June 17, 2025 after a comprehensive data review. Affected data includes names and Social Security Numbers. Total 28,018 individuals affected nationwide; 8 Maine residents. Written notifications sent July 8, 2025. IDX credit monitoring offered for 12 months.
Maine clockDiscovered Jun 17, 2025 → Filed with AG Jul 8, 202521d ✓ ME AG ≤30d21 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6e861a1c943467afIndiana State AGfiled 2025-07-08Verified
- bd_bf66e8a2a2c76dbfNew Hampshire State AGfiled 2025-07-08Verified
- bd_7157d0b87aafe27bVermont State AGfiled 2025-07-07(1d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1e740866-6470-42db-accf-2455ab040b94.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2025
- Raw hash
- deeb69660a05d7f1b5c56e31b219675d638d4343d98d37cafeab902502f910aa
Reporting entity
- Name
- North Carolina Board of Cosmetic Art Examinersnorm: north carolina board of cosmetic art examiners
- Industry
- Other Government Entity
Victim entity
- Name
- North Carolina Board of Cosmetic Art Examinersnorm: north carolina board of cosmetic art examiners
- Industry
- Other Government Entity
- Industry
- Governmentllm
Incident
- Discovered
- Jun 17, 2025
- Materiality determined
- —
- Notification sent
- Jul 8, 2025
- Affected individuals
- 8
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notification provided to relevant state regulatorsNotification provided to three major credit reporting agencies: Equifax, Experian, and TransUnion
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 17, 2025→ Filed with AG: Jul 8, 202521d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.