HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Endue Software
bd_2ba6e7caea77b873 · schema v1 · pii pii-v1
Full breach record for Endue Software →Endue Software notified consumers of a cybersecurity incident where an unauthorized actor accessed systems on Feb 16, 2025, copying files containing names, DOBs, SSNs, and medical record numbers. Endue secured systems, engaged law enforcement, and offered credit monitoring. No evidence of identity theft found.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_08920fbd0889d482Indiana State AGfiled 2025-04-11Verified
- bd_15dd0c0c8fb43bf4HHS OCRfiled 2025-04-11Verified
- bd_1ff35c438b26be88New Hampshire State AGfiled 2025-04-11Verified
- bd_3f9524f86d2e0052Maine State AGfiled 2025-04-11Verified
Show 3 more filings ↓Show fewer ↑
- bd_5bc86c50c5edfc76Vermont State AGfiled 2025-04-11Verified
- bd_7345eadbe357342dCalifornia State AGfiled 2025-04-11Verified
- bd_96d712f75f14a6b9Montana State AGfiled 2025-04-11Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-11-endue-software-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2025
- Raw hash
- 241a44ae824342b83a994548df3f86ad853659a3d0e90920063f3f84a7f26e96
Reporting entity
- Name
- Endue Softwarenorm: endue software
Victim entity
- Name
- Endue Softwarenorm: endue software
Incident
- Discovered
- Feb 17, 2025
- Materiality determined
- —
- Notification sent
- Apr 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- notified law enforcementproviding notice of this incident to relevant regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.