The Pierce County Library System 2025 data breach occurred when threat actors maintained unauthorized access to the Washington public-library network between April 15 and April 21, 2025 and stole personal data from its systems. PCLS investigated the nature, scope, and affected information. Public findings establish confirmed acquisition of data rather than only a possibility that records could have been viewed.
Pierce County Library System reported 340,101 affected individuals to the Maine Attorney General, and pwnCount and totalRecords use that official total. The population included library patrons, current and former employees, and their family members. Because fields differed by group, this record separates patron data from the more sensitive employee and family information; LeakData imports no personal records.
How Was the Incident Confirmed?
The PCLS incident statement, as quoted in reporting, says attackers accessed the library network and obtained certain data from its systems. After discovery, the organization investigated the nature and scope and identified affected information types. SecurityWeek independently reviewed the organization notice and regulator filing, reporting the access window, affected groups, and data fields.
The Maine Attorney General filing confirms a notification population of 340,101 and that written notices were being sent. PCLS did not publicly identify the attacker or initial technique, and no known ransomware group claimed the event. LeakData therefore confirms the theft while avoiding an unsupported attribution to a specific actor, malware family, or ransom demand.
When Did the Unauthorized Access Occur?
The investigation determined that threat actors accessed the PCLS network from April 15 through April 21, 2025. Certain data in the systems was acquired during this six-day window. breachDate is April 15, the beginning of the verified access range. Discovery and notification happened later, but the affected population is recorded as one incident linked to this access period.
After discovery, PCLS worked to determine the event's nature and scope, identify information that could have been affected, and meet notification duties. Public sources do not describe the first-entry vector, number of affected servers, or precise exfiltration method. Those missing details are not filled with assumptions in this record.
What Patron Data Was Affected?
For library patrons, the confirmed fields are names and dates of birth. Sources do not place borrowing histories, reading preferences, library-card passwords, email contents, or payment cards in the verified patron scope. Potentially sensitive library-use records are therefore not added merely because such information could exist in a library service.
A name and date of birth can support targeted phishing, account-recovery abuse, and matching with other datasets. Patrons receiving notices should verify messages that appear to come from PCLS and request additional identifying information. The two fields disclosed for patrons must not be automatically equated with the broader sensitive-data list for employees and family members.
What Employee and Family Information Was Involved?
For current and former employees and family members, the possible scope included names and dates of birth plus Social Security, driver's-license, and passport numbers. Financial information and credit-card details were also disclosed as affected categories. These identity and financial fields create lasting risks of identity theft, fraudulent accounts, and payment fraud.
Health-insurance and medical information was also involved for the employee and family group. The organization did not say every field appeared for every affected person, so the classes describe the potential group scope. The record does not imply that medical or financial data was present for all 340,101 people when patrons were publicly associated only with names and birth dates.
What Should Affected People Do?
PCLS offered affected individuals twelve months of free credit monitoring and identity-protection services. Notice recipients should check the enrollment deadline, review credit reports, and report unfamiliar accounts or transactions. If a Social Security, driver's-license, or passport number was involved, a security freeze, document-agency alert, and tax-account monitoring may be appropriate.
People whose health-insurance or medical information was involved should review statements for unfamiliar services and providers. If credit-card details were identified, replacement or enhanced monitoring can be discussed with the issuer. Calls and messages claiming to be from PCLS should be verified using contact information independently obtained from the official website before any link is opened.
How Should This LeakData Record Be Read?
pwnCount and totalRecords are 340,101, the total reported to the Maine Attorney General. The figure covers patrons, employees, and family members; sources did not publish separate counts for each group, so no subgroup totals are invented. Data classes are group-specific and do not mean every field appeared for every person.
importedRecordCount is zero; LeakData stores no names, birth dates, identity documents, Social security numbers, financial, card, insurance, or medical data. The entry presents the confirmed network access, theft, official person count, and protection guidance. If PCLS or a regulator publishes a more detailed final report, the entry vector and subgroup scope can be updated from that primary evidence.