HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Panorama Eyecare
bd_398e3ae8891cf770 · schema v1 · pii pii-v1
Full breach record for Panorama Eyecare →Panorama Eyecare notified consumers and Vermont AG of a breach where an unauthorized party accessed the internal network between May 22 and June 4, 2023. The incident may have exposed names, government IDs, and health information. The company engaged forensic investigators and offered credit monitoring.
Vermont clock✗ VT AG >45 bday12 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 368 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_37a20ef7141a0c8fLeak Sitelockbit_3filed 2023-07-11(330d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_69fc82cf197e9d9cMaine State AGfiled 2024-06-05Verified by operator
- bd_d080942e9d889006Montana State AGfiled 2024-06-05Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-05-panorama-eyecare-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 5, 2024
- Raw hash
- d3c7a801f569a6a3426094ea1aae5a5c733b1e4f65a26b1206f7cbd9a3a48f51
Reporting entity
- Name
- Panorama Eyecarenorm: panorama eyecare
- Domain
- panoramaeyecare.com
Victim entity
- Name
- Panorama Eyecarenorm: panorama eyecare
- Domain
- panoramaeyecare.com
Incident
- Discovered
- Jun 3, 2023
- Materiality determined
- Jun 5, 2024
- Notification sent
- Jun 5, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 months(368 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.