MalwareRansomwareRansom DemandedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Ohio History Connection
bd_f6e7484647a602c9 · schema v1 · pii pii-v1
Full breach record for Ohio History Connection →Ohio History Connection suffered a ransomware attack in early July 2023. Cybercriminals encrypted data servers and demanded a multi-million dollar ransom. The breach exposed names, addresses, and SSNs of ~7,600 current/former employees and vendors, plus check images. OHC notified the FBI, engaged forensic consultants, and offered one year of credit monitoring.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 51 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_15e2608dae4ada29Leak Sitelockbit_3filed 2023-07-27(27d gap)Verified by operator
- bd_cc0d34f222cd3fd2Leak Sitelockbit_3filed 2023-07-03(51d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-23-ohio-historical-society-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- 85206c2d16230be3531eedc50da908130d824522e5c6658221d123233d3ec87d
Reporting entity
- Name
- Ohio History Connectionnorm: ohio history connection
- Domain
- ohiohistory.org
Victim entity
- Name
- Ohio History Connectionnorm: ohio history connection
- Domain
- ohiohistory.org
Incident
- Discovered
- Jul 1, 2023
- Materiality determined
- —
- Notification sent
- Aug 23, 2023
- Affected individuals
- 7,600
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.