HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
Carney Badley Spellman, PS
bd_2ae891dfed5a717e · schema v1 · pii pii-v1
Full breach record for Carney Badley Spellman, PS →Carney Badley Spellman, PS reported a data security incident where unauthorized access to personal information (names) occurred. Suspicious activity was detected around May 2, 2025. The firm engaged digital forensics specialists and secured its environment. Notification to affected individuals was completed by June 18, 2025. No evidence of misuse was found. Complimentary credit monitoring via TransUnion was offered.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-03-carney-badley-spellman-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- 8113d1bb0074283e20e442d0069e43c28364ef77de17ff7532f79b976e73fa82
Reporting entity
- Name
- Carney Badley Spellman, PSnorm: carney badley spellman ps
Victim entity
- Name
- Carney Badley Spellman, PSnorm: carney badley spellman ps
Incident
- Discovered
- May 2, 2025
- Materiality determined
- Jul 3, 2025
- Notification sent
- Jun 18, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.