HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
KEMPER SPORTS MANAGEMENT, INC.
bd_0c9ffd2ebab2b50d · schema v1 · pii pii-v1
Full breach record for KEMPER SPORTS MANAGEMENT, INC. →Kemper Sports Management, LLC notified consumers of a security incident discovered on April 1, 2024, where an unauthorized user accessed systems containing names and Social Security numbers. The company launched an investigation, secured systems, and offered 12 months of credit monitoring. No indication of misuse was found at the time of notice.
Vermont clock✗ VT AG >45 bday23 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_118b7f9dd4b6c144New Hampshire State AGfiled 2024-09-09Verified
- bd_2f5967dc4a369101Indiana State AGfiled 2024-09-09Verified
- bd_31439c4b32656221Maine State AGfiled 2024-09-09Candidate
- bd_5dbe66d152439efaOregon State AGfiled 2024-09-09Verified
Show 3 more filings ↓Show fewer ↑
- bd_7c361bd2e0b92b7fMontana State AGfiled 2024-09-09Verified
- bd_91b7817624b193e2Washington State AGfiled 2024-09-09Verified
- bd_f0f75adbc0018fc8California State AGfiled 2024-09-09Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-09-kemper-sports-management-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 9, 2024
- Raw hash
- 51d5cb569399f82d0c36c9b3455dd026ae1c0d71d5c68eb95def2cc13f2c4ab7
Reporting entity
- Name
- KEMPER SPORTS MANAGEMENT, INC.norm: kemper sports management
- Domain
- kempersports.com
Victim entity
- Name
- KEMPER SPORTS MANAGEMENT, INC.norm: kemper sports management
- Domain
- kempersports.com
Incident
- Discovered
- Apr 1, 2024
- Materiality determined
- —
- Notification sent
- Sep 9, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notify applicable regulatory authorities where necessary
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(161 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.