HackingTargetedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASICMediumContained
TECTA AMERICA CORP.
bd_0235ebf5d2474c0c · schema v1 · pii pii-v1
Full breach record for TECTA AMERICA CORP. →Tecta America Corp notified Vermont AG of a cyber incident occurring Sept 20–Oct 2, 2024, discovered Oct 1, 2024. Unauthorized actors accessed files containing SSNs, driver's license numbers, financial account info, and names. Tecta notified federal law enforcement and offered credit monitoring. No specific total count disclosed; ~18 Rhode Island residents impacted.
Vermont clock✗ VT AG >45 bday13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 93 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_037bec5f9c0a1cd5New Hampshire State AGfiled 2025-01-02Verified
- bd_a811545bbb1982feIndiana State AGfiled 2025-01-02Verified
- bd_d0dc72cf9f32177cCalifornia State AGfiled 2025-01-02Verified
- bd_f9cc29839697ec80Maine State AGfiled 2025-01-02Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-01-02-tecta-america-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 2, 2025
- Raw hash
- 4d5fa121dc0b5234dcbe2564804b8c3e03a0afa421f3eabd72662932e5c1ceba
Reporting entity
- Name
- TECTA AMERICA CORP.norm: tecta america
- Domain
- tectaamerica.com
Victim entity
- Name
- TECTA AMERICA CORP.norm: tecta america
- Domain
- tectaamerica.com
Incident
- Discovered
- Oct 1, 2024
- Materiality determined
- —
- Notification sent
- Jan 2, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notifying state regulators, as required
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.