Description

The Pierce County Library System (PCLS) has announced a major data breach affecting more than 340,000 individuals, including library patrons, employees, former employees, and some of their family members. The incident occurred between April 15 and April 21, 2025, when threat actors gained unauthorized access to PCLS’s network and extracted sensitive data from its systems. After detecting unusual activity, PCLS immediately launched an internal investigation to determine the scope of the compromise, the categories of affected data, and the extent of threat actor access. The organization then publicly disclosed the breach through a formal incident notice while coordinating with regulatory authorities, including the Maine Attorney General’s Office. The breach exposed varying degrees of sensitive information depending on the group impacted. For library patrons, the compromised data included basic personal details such as names and dates of birth, which still pose risks such as identity profiling or targeted phishing attempts. In contrast, the exposure for current and former employees and their family members is far more severe, involving Social Security numbers, driver’s license and passport numbers, credit card and financial information, as well as health insurance and medical details. Such data enables identity theft, financial fraud, and long-term privacy impacts. PCLS has begun issuing written notification letters to all 340,101 impacted individuals and is providing 12 months of free credit monitoring and identity-protection services to mitigate potential harm. While PCLS confirmed the timeframe and scope of the intrusion, it has not disclosed the identity of the attackers or the specific intrusion method utilized. No known ransomware or data-extortion groups have claimed responsibility for the breach as of now. The absence of attribution leaves open the possibility of financially motivated cybercriminals or opportunistic threat actors exploiting vulnerabilities within the library’s IT environment. PCLS continues to work with cybersecurity specialists to assess residual risks and strengthen its security posture. The organization urges affected individuals to remain vigilant for suspicious activity involving their personal or financial accounts.