HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
American Association of Colleges of Osteopathic Medicine
bd_e8b87fa5585fb708 · schema v1 · pii pii-v1
Full breach record for American Association of Colleges of Osteopathic Medicine →American Association of Colleges of Osteopathic Medicine (AACOM) discovered unauthorized access to an employee email account on September 26, 2024. The incident involved potential access to emails and attachments containing personal information. AACOM secured the email environment, engaged independent experts for investigation, and offered identity protection services to affected individuals. No evidence of misuse was found.
California clockDiscovered Sep 26, 2024 → Notified Apr 8, 2025194d ✗ CA 60-day late28 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0f81799057ac7a06Indiana State AGfiled 2025-04-08Verified
- bd_31778ded704f2f6dIowa State AGfiled 2025-04-08Candidate
- bd_6ab7b871b501d6bdVermont State AGfiled 2025-04-08Verified
- bd_d68c22df129ea118New Hampshire State AGfiled 2025-04-08Verified
Show 3 more filings ↓Show fewer ↑
- bd_dab067214f98a919Oregon State AGfiled 2025-04-08Verified
- bd_ebcca748e75e0a1fMaine State AGfiled 2025-04-08Verified
- bd_f350f7480c2e9683Washington State AGfiled 2025-04-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601144
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2025
- Raw hash
- 38cd6980a9582f9525807b52993e922fe7fa4570edadc8684cfdbc841056705b
Reporting entity
- Name
- American Association of Colleges of Osteopathic Medicinenorm: american association of colleges of osteopathic medicine
Victim entity
- Name
- American Association of Colleges of Osteopathic Medicinenorm: american association of colleges of osteopathic medicine
Incident
- Discovered
- Sep 26, 2024
- Materiality determined
- —
- Notification sent
- Apr 8, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 weeks(194 days from discovery to filing)
- Compliance flags
- CA 60-day late · 194d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 26, 2024→ Notified: Apr 8, 2025194d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.