HackingData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Graebel Companies, Inc.
bd_362736f9c58a9c4a · schema v1 · pii pii-v1
Full breach record for Graebel Companies, Inc. →Graebel Companies, Inc. notified consumers of a cybersecurity incident occurring between December 19-22, 2024, where unauthorized actors accessed files containing personal information. Graebel secured its network, engaged in investigations, and reported the incident to federal law enforcement. Affected individuals are offered 24 months of credit monitoring through TransUnion. The specific data types were redacted in the template but typically include identity and government identifiers.
Vermont clock✗ VT AG >45 bday47 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_22d338674a0c0fa3Maine State AGfiled 2025-11-10Candidate
- bd_2c087f5658292a9bNew Hampshire State AGfiled 2025-11-10Verified
- bd_3338885415a19f86Indiana State AGfiled 2025-11-10Verified
- bd_8a7899be71a5b644Montana State AGfiled 2025-11-10Candidate
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_8f785a8bea830a5eTexas State AGfiled 2025-11-12(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-10-graebel-companies-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 10, 2025
- Raw hash
- e1ccc1fa5eaf7f0aabf83a74c031e8cb6c1a0a83d0a52232f8d9dff4edb33f3b
Reporting entity
- Name
- Graebel Companies, Inc.norm: graebel companies
Victim entity
- Name
- Graebel Companies, Inc.norm: graebel companies
Incident
- Discovered
- Dec 19, 2024
- Materiality determined
- —
- Notification sent
- Nov 10, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported this event to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 47 weeks(326 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.