HackingStolen CredentialsCapture Stored DataData ExfiltratedTargetedPIIIDENTITY_BASICLowContained
The Alcohol & Drug Testing Service
bd_032ba889daf3b6df · schema v1 · pii pii-v1
Full breach record for The Alcohol & Drug Testing Service →The Alcohol & Drug Testing Service (TADTS) disclosed a cybersecurity incident in July 2024 where an unauthorized actor downloaded personal information, including names and impacted data elements, from its systems. TADTS reported the incident to federal law enforcement, engaged cybersecurity professionals, reset passwords, and enhanced endpoint detection. No identity theft or fraud has been confirmed.
Vermont clock✗ VT AG >45 bday12 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_70bb2c27a097250bIndiana State AGfiled 2025-07-17Verified
- bd_a43501eb14f849b3Maine State AGfiled 2025-07-17Candidate
- bd_01a2fb67a87c9b5dTexas State AGfiled 2025-07-18(1d gap)Verified
- bd_1c65f70955be2f75New Hampshire State AGfiled 2025-07-21(4d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-17-alcohol-drug-testing-service-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2025
- Raw hash
- 3eb65233a288d6942d6b6865bdbebe0d32f9e3bf7306c74f12015af01467fcf5
Reporting entity
- Name
- The Alcohol & Drug Testing Servicenorm: the alcohol drug testing service
Victim entity
- Name
- The Alcohol & Drug Testing Servicenorm: the alcohol drug testing service
Incident
- Discovered
- Jul 9, 2024
- Materiality determined
- —
- Notification sent
- Jul 17, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this matter to federal law enforcementreported this Incident to relevant government agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 months(373 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.