HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Layman, Diener & Borntrager Insurance Agency, Inc.
bd_09cf1c909f636d97 · schema v1 · pii pii-v1
Full breach record for Layman, Diener & Borntrager Insurance Agency, Inc. →Layman, Diener, and Borntrager Insurance Agency reported an internal system breach occurring on May 17, 2021, discovered on September 9, 2021. The incident compromised the names and driver's license numbers of 7,909 individuals, including 7 Maine residents. The agency provided 12 months of credit monitoring and identity protection services to affected parties.
Maine clockDiscovered Sep 9, 2021 → Filed with AG Oct 28, 202149d ⏱ ME AG >30d7 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_915c7f82fdbc51e5Maine State AGfiled 2021-11-01(4d gap)Verified by operator
- bd_a18ef0eeebaefedeMontana State AGfiled 2021-09-28(30d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/7a898edc-b476-430f-88f4-2e1b6549435a.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 28, 2021
- Raw hash
- a0b9d25918610b3153f5586a26b5cc43fa494c24e1130e67fc13b79389a89d2f
Reporting entity
- Name
- Layman, Diener & Borntrager Insurance Agency, Inc.norm: layman diener borntrager insurance agency
Victim entity
- Name
- Layman, Diener & Borntrager Insurance Agency, Inc.norm: layman diener borntrager insurance agency
Incident
- Discovered
- Sep 9, 2021
- Materiality determined
- —
- Notification sent
- Oct 29, 2021
- Affected individuals
- 7,909
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- ME AG >30d · 49d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 9, 2021→ Filed with AG: Oct 28, 202149d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.