HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NetJets Aviation - NetJets Services
bd_19f2268bcf6e4197 · schema v1 · pii pii-v1
Full breach record for NetJets Aviation - NetJets Services →NetJets Aviation reported unauthorized access to an employee's Microsoft 365 account on March 12, 2025. The attacker viewed and obtained files containing customers' names and Social Security numbers. NetJets secured the account, engaged a cybersecurity firm, notified law enforcement, and offered one year of credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-05-30-netjets-aviation-netjets-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 30, 2025
- Raw hash
- 7992fea03e4dfc649d22441d9520d27b8895ebe266a0d1fd95e16741a2142c0c
Reporting entity
- Name
- NetJets Aviation - NetJets Servicesnorm: netjets aviation netjets
Victim entity
- Name
- NetJets Aviation - NetJets Servicesnorm: netjets aviation netjets
Incident
- Discovered
- Mar 12, 2025
- Materiality determined
- —
- Notification sent
- May 30, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement and is supporting its investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.