HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Academic Urology & Urogynecology of Arizona
bd_ebab26127472dfad · schema v1 · pii pii-v1
Full breach record for Academic Urology & Urogynecology of Arizona →Academic Urology & Urogynecology of Arizona notified consumers of a cybersecurity incident occurring between May 18-22, 2025. Unauthorized access potentially exposed names and protected health information. The organization engaged external forensic investigators, secured its environment, and is offering complimentary credit monitoring and identity theft protection services to affected individuals.
Vermont clock✗ VT AG >45 bday38 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by inc_ransom about this victim predates this filing by 240 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f978d5854d2557eeNew Hampshire State AGfiled 2026-02-13(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-12-academic-urology-urogynecology-arizona-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 12, 2026
- Raw hash
- 1b6fbc93206de99f1fd3e4ac436c658c85b3a750e4e0efd0d3edc59f3e074935
Reporting entity
- Name
- Academic Urology & Urogynecology of Arizonanorm: academic urology urogynecology of arizona
- Domain
- academicuroaz.com
Victim entity
- Name
- Academic Urology & Urogynecology of Arizonanorm: academic urology urogynecology of arizona
- Domain
- academicuroaz.com
Incident
- Discovered
- May 22, 2025
- Materiality determined
- Feb 12, 2026
- Notification sent
- Feb 12, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 38 weeks(266 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.