Appalachian Regional Commission
ent_71ecc55668238058
Disclosures
8
State AG · Leak Site · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
937
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Appalachian Regional Commission
- Normalized
- appalachian regional commission— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- arc.gov
Disclosure history (8)newest first
- New Hampshire State AGas victim2025-07-16
Appalachian Regional Commission (ARC) notified the NH Attorney General of a cybersecurity incident discovered on April 10, 2025, involving malware deployment and unauthorized data access/exfiltration. One New Hampshire resident was affected, with potential exposure of name, address, SSN, bank account/routing numbers, and medical information. ARC contained the threat, engaged forensic investigators, contacted law enforcement, and is offering 24 months of credit monitoring.
- Maine State AGas victim2025-07-15
Appalachian Regional Commission (ARC) reported a cybersecurity incident on April 10, 2025, involving malware deployment and unauthorized data access. The breach affected 937 individuals, including 1 Maine resident. Personal information exposed included names, SSNs, driver's licenses, and medical data. ARC engaged forensic investigators, notified law enforcement, and offered 24 months of credit monitoring via IDX.
- Nebraska State AGas victim2025-07-15
Appalachian Regional Commission (ARC) notified Nebraska AG on July 15, 2025, of a cybersecurity incident discovered April 10, 2025, involving malware deployment. Unauthorized access occurred on April 10, 2025, resulting in data removal. Affected data includes names, addresses, DOB, SSN, driver's licenses, and medical info. ARC engaged forensic investigators, contacted law enforcement, and offers 24 months of credit monitoring. Incident status is contained.
- Vermont State AGas victim2025-07-15
The Appalachian Regional Commission (ARC) notified consumers of a data security incident involving malware deployment on April 10, 2025. An unauthorized party accessed and removed data, including names, addresses, dates of birth, Social Security numbers, driver's license/state ID numbers, and potentially medical or treatment information. ARC contained the threat, engaged forensic investigators, and offered 24 months of credit monitoring.
- Indiana State AGas victim2025-07-15
Appalachian Regional Commission reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-10 and was reported on 2025-07-15. 2 Indiana residents were affected. 937 individuals affected in total.
- Massachusetts State AGas victim2025-07-15
Appalachian Regional Commission reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-07-15. 3 Massachusetts residents were affected.
- GLOBALLeak Siteas victim2025-04-24
Appalachian Regional Commission is an economic development agency of the federal government and 13 state governments focusing on 423 counties across the Appalachian Region. Appalachian Regional Commission corporate office is located in 1666 Connecticut Ave NW Ste 700, Washington, District of Columbia, 20009, United States and has 110 employees.
- GLOBALLeak Siteas victim2025-04-10
Appalachian Regional Commission is an economic development agency of the federal government and 13 state governments focusing on 423 counties across the Appalachian Region. Appalachian Regional Commission corporate office is located in 1666 Connecticut Ave NW Ste 700, Washington, District of Columbia, 20009, United States and has 110 employees.