Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICCREDENTIALSLowContained
Integral Federal Inc.
bd_196c2761a331dbab · schema v1 · pii pii-v1
Full breach record for Integral Federal Inc. →Integral Federal Inc. notified consumers of a data breach involving unauthorized access to employee email accounts between Feb 11 and Mar 30, 2023. The incident likely resulted from phishing, compromising credentials. Affected data includes names and other personal information. Integral Federal offered 24 months of credit monitoring via Experian and is implementing additional security measures.
Vermont clock✗ VT AG >45 bday13 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_28ad276a2b83a969Indiana State AGfiled 2024-04-25Verified
- bd_612f0c0ada1d2710Montana State AGfiled 2024-04-25Candidate
- bd_82625411e9315de1Maine State AGfiled 2024-04-25Verified
- bd_bae8f3126052e2b8New Hampshire State AGfiled 2024-04-25Verified
Show 1 more filing ↓Show fewer ↑up to 69d gap
- bd_9ba8ae660b6b5a7dVermont State AGfiled 2024-07-03(69d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-25-integral-federal-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2024
- Raw hash
- b8be23fc9a8085a2f0770d954bde1e13e50d14d1c74b5f4d1104b430fffccad5
Reporting entity
- Name
- Integral Federal Inc.norm: integral federal
Victim entity
- Name
- Integral Federal Inc.norm: integral federal
Incident
- Discovered
- Mar 24, 2023
- Materiality determined
- —
- Notification sent
- Apr 25, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- notifying state regulators, as required
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 months(398 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.