HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Loren D. Stark Company
bd_2f0d72e5b8344ef3 · schema v1 · pii pii-v1
Full breach record for Loren D. Stark Company →Loren D. Stark Company, a retirement plan consulting firm, disclosed a data breach occurring on October 18, 2022, involving unauthorized access to systems containing full names and Social Security numbers. The company engaged third-party forensic investigators, secured its network, and offered Equifax Credit Watch Gold identity protection services to affected individuals. Notification was filed with the Vermont Attorney General on August 4, 2023.
Vermont clock✗ VT AG >45 bday41 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_13fb89d1966d8b01California State AGfiled 2023-08-04Candidate
- bd_e4474ca6b746f53aMaine State AGfiled 2023-08-04Verified by operator
- bd_a06d159a925776c2Montana State AGfiled 2023-08-05(1d gap)Verified
- bd_9d59217bd4ac2f77New Hampshire State AGfiled 2023-08-11(7d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 19d gap
- bd_fb66f822dc808240South Carolina State AGfiled 2023-08-23(19d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-04-loren-d-stark-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 4, 2023
- Raw hash
- 0ed3d3e4e4bcb9cab498d2bbc9fe4750cb2d5dd09edced9ecb16b9f6bc506827
Reporting entity
- Name
- Loren D. Stark Companynorm: loren d stark
Victim entity
- Name
- Loren D. Stark Companynorm: loren d stark
Incident
- Discovered
- Oct 18, 2022
- Materiality determined
- Jun 16, 2023
- Notification sent
- Aug 4, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(290 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.