HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
VECTOR SECURITY, INC.
bd_0548aa5296b2b44a · schema v1 · pii pii-v1
Full breach record for VECTOR SECURITY, INC. →Vector Security, Inc. notified consumers of a cybersecurity incident where unauthorized access to IT systems occurred as early as mid-December 2024. The incident potentially exposed names, SSNs, driver's licenses, credit/debit card numbers, tax IDs, and medical/health insurance information. Vector Security contained the breach, notified federal law enforcement, engaged cybersecurity specialists, and offered 12 months of credit monitoring and fraud assistance.
Vermont clock✗ VT AG >45 bday33 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_ae672ecb9a1d63cdIndiana State AGfiled 2025-08-01Verified
- bd_cb16e052ad7341c3Maine State AGfiled 2025-08-01Candidate
- bd_e38ae76d117aecaeNew Hampshire State AGfiled 2025-08-01Verified
- bd_6c8340ceb0a3330cTexas State AGfiled 2025-08-04(3d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-01-vector-security-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2025
- Raw hash
- 606d0c7a46b40e441fbe02547af227f7421ee2c1d731fd2cbe73e61130998914
Reporting entity
- Name
- VECTOR SECURITY, INC.norm: vector security
Victim entity
- Name
- VECTOR SECURITY, INC.norm: vector security
Incident
- Discovered
- Dec 15, 2024
- Materiality determined
- —
- Notification sent
- Aug 1, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified U.S. federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 33 weeks(229 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.