Lumitex, Inc.
bd_2a9bd4e3650e0fa0 · schema v1 · pii pii-v1
Full breach record for Lumitex, Inc. →Lumitex, Inc. disclosed a cybersecurity incident discovered on June 6, 2025, involving unauthorized access to its network. The attacker exploited a public-facing application and used stolen credentials to exfiltrate data. Affected individuals' names, addresses, SSNs, driver's license numbers, and financial account information were compromised. Lumitex notified affected individuals in Vermont, New York, Massachusetts, Connecticut, New Hampshire, Maine, and Rhode Island. The company engaged Mandiant for forensic investigation and offered 24 months of credit monitoring and identity theft protection.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_14422696b1f4a69aNew Hampshire State AGfiled 2025-08-15Verified
- bd_ae34e3e38722f69fMaine State AGfiled 2025-08-15Candidate
- bd_f28766ad6a774dc7Indiana State AGfiled 2025-08-15Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-15-lumitex-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2025
- Raw hash
- 373ca0d24db3529ea17a9586f243d61f79928bfe3769c13d6b312ec59c2000af
Reporting entity
- Name
- Lumitex, Inc.norm: lumitex
Victim entity
- Name
- Lumitex, Inc.norm: lumitex
Incident
- Discovered
- Jun 6, 2025
- Materiality determined
- —
- Notification sent
- Aug 15, 2025
- Affected individuals
- 10,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Vermont Attorney GeneralNotified New York Attorney GeneralNotified Massachusetts Attorney GeneralNotified Connecticut Attorney GeneralNotified New Hampshire Attorney GeneralNotified Maine Attorney GeneralNotified Rhode Island Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.