HackingDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
Siegel Group
bd_35e7cd347a0e7f64 · schema v1 · pii pii-v1
Full breach record for Siegel Group →The Siegel Group, Inc. disclosed a cybersecurity incident where an unauthorized actor viewed and/or copied files containing employee PII, including SSNs, DOBs, passport numbers, and medical information, between Jan 28 and Feb 2, 2025. The company reported the incident to law enforcement, engaged cybersecurity specialists, and offered credit monitoring services to affected employees.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by interlock about this victim predates this filing by 37 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_a25dc26b9d0093dcLeak Siteinterlockfiled 2025-02-25(33d gap)Verified
- bd_1aea4a737e42a080Leak Siteinterlockfiled 2025-02-21(37d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_5fe70eb9e4daeb98Indiana State AGfiled 2025-03-31Verified
- bd_00241e6764a13365Maine State AGfiled 2025-04-01(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-31-siegel-group-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2025
- Raw hash
- 83739fac1a768f265bb67356aed297db55679e065b83243fd8e0844f78986034
Reporting entity
- Name
- Siegel Groupnorm: siegel group
- Domain
- siegelcompanies.com
Victim entity
- Name
- Siegel Groupnorm: siegel group
- Domain
- siegelcompanies.com
Incident
- Discovered
- Feb 2, 2025
- Materiality determined
- —
- Notification sent
- Mar 31, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported the event to law enforcement
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.