Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
J.M. Forbes & Co.
bd_2d8fdc40759510b0 · schema v1 · pii pii-v1
Full breach record for J.M. Forbes & Co. →J.M. Forbes & Co. notified consumers of a security incident detected on November 17, 2025, involving unauthorized access to an employee email account. The breach was part of a business email compromise attempt via social engineering. Affected data included names, addresses, Social Security numbers, and account numbers. No fraudulent transactions occurred. The company engaged forensic experts and offers two years of credit monitoring.
Vermont clock✗ VT AG >45 bday20 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_66f15480d78ef9f6New Hampshire State AGfiled 2026-04-07Verified
- bd_ba4b31877e8d09b1Maine State AGfiled 2026-04-07Verified by operator
- bd_a5dc2e414705c04dNew Hampshire State AGfiled 2026-07-06(90d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-04-07-jm-forbes-co-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2026
- Raw hash
- bb1f2b7195ca2f1e347dd8a988459a23e56e86be90f64b332b428a2e2b51aff8
Reporting entity
- Name
- J.M. Forbes & Co.norm: jm forbes
- Domain
- jmforbes.com
Victim entity
- Name
- J.M. Forbes & Co.norm: jm forbes
- Domain
- jmforbes.com
Incident
- Discovered
- Nov 17, 2025
- Materiality determined
- —
- Notification sent
- Apr 7, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.