HackingData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Columbus Foundation
bd_fae7d45522d0c5c5 · schema v1 · pii pii-v1
Full breach record for The Columbus Foundation →The Columbus Foundation notified consumers of a July 2023 security incident where an unauthorized external party posted direct internet links to internal data for Gifts of Kindness and Emergency Assistance programs. Compromised data included names, addresses, driver's license numbers, and Social Security numbers. No evidence of fraudulent misuse was found. The Foundation removed access, engaged legal/technical counsel, and offered 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6e85b5718c2dbf4cMontana State AGfiled 2023-09-11(3d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-08-columbus-foundation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 8, 2023
- Raw hash
- 3206e5d592f82f0f4c8e57fa1aabf1e44ce52b8a80af919559cf08eb334a5a9b
Reporting entity
- Name
- The Columbus Foundationnorm: the columbus
Victim entity
- Name
- The Columbus Foundationnorm: the columbus
Incident
- Discovered
- Jul 1, 2023
- Materiality determined
- —
- Notification sent
- Sep 8, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.