HackingStolen CredentialsTargetedIDENTITY_BASICPIILowContained
Pacific Center for Financial Services
bd_2c070320d6ebdcec · schema v1 · pii pii-v1
Full breach record for Pacific Center for Financial Services →Pacific Center for Financial Services notified consumers of unauthorized access to an employee email account between Sept 25, 2024 and March 11, 2025. The incident involved compromised credentials. Affected data included names and other personal information. PCFS secured the account, notified law enforcement, and offered 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday41 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5b85b867f7f95460Indiana State AGfiled 2025-07-08Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-08-pacific-center-financial-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2025
- Raw hash
- b496dc81c4c93355512e283282b3781d2020a8d200b808e2951176bb5e1b40cd
Reporting entity
- Name
- Pacific Center for Financial Servicesnorm: pacific center for financial
Victim entity
- Name
- Pacific Center for Financial Servicesnorm: pacific center for financial
Incident
- Discovered
- Sep 25, 2024
- Materiality determined
- —
- Notification sent
- Jul 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(286 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.