HackingData ExfiltratedPIIFINANCIAL_ACCOUNTLowContained
Systems East, Inc.
bd_35d2d3bab9fb5f29 · schema v1 · pii pii-v1
Full breach record for Systems East, Inc. →Systems East, Inc. notified consumers that on August 25, 2023, an unknown individual temporarily accessed its network and copied an encrypted database file containing names and payment card information. The breach did not involve SSNs or driver's licenses. Systems East notified card providers and implemented security enhancements. The notice was filed with the Vermont Attorney General on November 16, 2023.
Vermont clock✗ VT AG >45 bday12 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_112c0a336a9f0b37California State AGfiled 2023-11-16Candidate
- bd_336709c286ddb289New Hampshire State AGfiled 2023-11-16Verified
- bd_3cd8525ae90d4935Maine State AGfiled 2023-11-16Verified
- bd_9db41fccc5975764Oregon State AGfiled 2023-11-16Verified
Show 2 more filings ↓Show fewer ↑
- bd_dd9f817dec80faeaWashington State AGfiled 2023-11-16Verified
- bd_fe09656762736c34Montana State AGfiled 2023-11-16Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-11-16-systems-east-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 16, 2023
- Raw hash
- 28489dd86063ba1ce1c8836e5f51d4ca461b761345d26788ccd165e4f1e5d7ed
Reporting entity
- Name
- Systems East, Inc.norm: systems east
Victim entity
- Name
- Systems East, Inc.norm: systems east
Incident
- Discovered
- Aug 25, 2023
- Materiality determined
- —
- Notification sent
- Nov 16, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the payment card providers (Visa, Mastercard, American Express, and Discover)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.