Vertafore
bd_0b6fb2d524526bb7 · schema v1 · pii pii-v1
Full breach record for Vertafore →Vertafore discovered a configuration error in its QQCatalyst product on November 30, 2020, leading to unauthorized public access to reports, forms, and potentially insurance applications. Impacted data included names, addresses, birthdates, driver's license numbers, and potentially SSNs and financial account info. Vertafore fixed the error, engaged forensic investigators, notified federal law enforcement, and offered one year of free identity monitoring via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 30, 2020
Discovered
Jun 16, 2021
Filed
vs. sector median
+10 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- South Carolina State AGbd_8c3393904c1de7c72021-07-08 · +22dVerified
- New Hampshire State AGbd_e05b9e1eb99587362021-07-09 · +23dVerified
- Montana State AGbd_46b0579fff296ea12021-08-09 · +54dVerified
- New Hampshire State AGbd_b417a50418164b432021-09-23 · +99dVerified
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Jun 16 (MT), last Sep 23 (NH) — a 99-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.