HackingData ExfiltratedPIIIDENTITY_BASICLowContained
Intrepid Sea, Air & Space Museum
bd_f49c8cc28846af35 · schema v1 · pii pii-v1
Full breach record for Intrepid Sea, Air & Space Museum →Intrepid Museum Foundation, Inc. notified consumers of a cybersecurity incident detected on December 3, 2023. An unauthorized third party accessed the network on December 2, 2023, and downloaded files containing personal information including names. The organization engaged external cybersecurity experts, contained the incident, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring services.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 185 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_481dc1623be371efLeak Siteplayfiled 2023-12-07(185d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_8ef651d4babc57bcIndiana State AGfiled 2024-06-10Verified
- bd_0a33cb0c5c76405eNew Hampshire State AGfiled 2024-06-17(7d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-10-intrepid-museum-foundation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2024
- Raw hash
- d1e00e12072f35f35aa256a5b1670197a90d1832e4660e7c9c0127bf932d7fdc
Reporting entity
- Name
- Intrepid Sea, Air & Space Museumnorm: intrepid sea air space museum
- Domain
- intrepidmuseum.org
Victim entity
- Name
- Intrepid Sea, Air & Space Museumnorm: intrepid sea air space museum
- Domain
- intrepidmuseum.org
Incident
- Discovered
- Dec 3, 2023
- Materiality determined
- —
- Notification sent
- Jun 10, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 weeks(190 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.