DisclosureLens
Social EngineeringProfessional ServicesProfessional ServicesPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDMediumContained

StrateBen

bd_06e53b4b0dc37169 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 3, 2025

Filed

Mar 26, 2026

To disclose

16 weeks

Affected

2state residents only

Linked

2 filings

Confidence

67%
Full breach record for StrateBen

STRATeBEN, Inc. disclosed a phishing incident affecting 2 Vermont residents. An employee's Microsoft 365 account was compromised between August 14 and November 9, 2025, exposing names, Social Security numbers, and dates of birth. STRATeBEN secured the account, engaged a third-party cybersecurity firm, and mailed notifications on March 26, 2026, offering one year of credit monitoring.

Vermont clock VT AG >45 bday16 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 111 days
discovery → filing · 16 weeks / 113 days

Aug 14, 2025

Begins

Dec 3, 2025

Discovered

Mar 26, 2026

Filed

vs. sector median

2 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGMar 26 · first
Vermont State AGMar 26 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.