HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
MWI Veterinary Supply, Inc.
bd_106866268166cc20 · schema v1 · pii pii-v1
Full breach record for MWI Veterinary Supply, Inc. →MWI Veterinary Supply, Inc. reported a data security incident confirmed on September 30, 2024, involving personal information of employees, dependents, and customers. Data accessed included names, addresses, SSNs, driver's license info, and health insurance details. The incident is contained. MWI engaged cybersecurity experts, law enforcement, and legal counsel, and is offering 24 months of credit monitoring via Experian.
Leak gap clock✗ Leak >180d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lorenz about this victim predates this filing by 637 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_881516599e930adbMaine State AGfiled 2024-11-04Candidate
- bd_c607081831255b90Montana State AGfiled 2024-11-04Candidate
- bd_e02a7dd25f3a1181California State AGfiled 2024-11-04Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-04-mwi-veterinary-supply-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 4, 2024
- Raw hash
- b06288c2f3e682097e0868c975e1b96846cad2bc6d19d2317d60766a81f87ce8
Reporting entity
- Name
- MWI Veterinary Supply, Inc.norm: mwi veterinary supply
Victim entity
- Name
- MWI Veterinary Supply, Inc.norm: mwi veterinary supply
Incident
- Discovered
- Sep 30, 2024
- Materiality determined
- —
- Notification sent
- Nov 4, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- investigation with the assistance of law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- Leak >180dVT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.