Social EngineeringPhishingDelayed DiscoveryIDENTITY_BASICLowContained
Bridges Hospice
bd_1449f67808f2bce5 · schema v1 · pii pii-v1
Full breach record for Bridges Hospice →Bridges Experience, Inc. notified consumers of a security incident where an unauthorized party accessed employee email accounts between December 2, 2024, and January 22, 2025. The breach exposed full names. Bridges EXP engaged cybersecurity professionals and is offering one year of Equifax Credit Watch Gold monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday23 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_0da26962cbbba4c6Delaware State AGfiled 2025-06-26Verified
- bd_12807c4a6d92e71bOregon State AGfiled 2025-06-26Candidate
- bd_229a42b3a6021fc6Indiana State AGfiled 2025-06-26Verified
- bd_3db6a39547dc7f08Montana State AGfiled 2025-06-26Verified by operator
Show 4 more filings ↓Show fewer ↑up to 5d gap
- bd_4a3806f82b493cfaCalifornia State AGfiled 2025-06-26Verified
- bd_55d07a6af1f99a5cWashington State AGfiled 2025-06-26Verified by operator
- bd_64e4f040a8df019cNew Hampshire State AGfiled 2025-06-30(4d gap)Verified
- bd_1ef98a8f5a0c9efaTexas State AGfiled 2025-07-01(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-06-26-bridges-experience-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2025
- Raw hash
- aa58d312e2bf62e0d42e8abe0486da22eccdf316dde5b650efdb72993a4747e4
Reporting entity
- Name
- Bridges Hospicenorm: bridges hospice
- Domain
- bridgeshospice.org
Victim entity
- Name
- Bridges Hospicenorm: bridges hospice
- Domain
- bridgeshospice.org
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.