HackingTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
LiveRez
bd_3c863c38ddb6766d · schema v1 · pii pii-v1
Full breach record for LiveRez →LiveRez, a vacation rental management software provider, disclosed a security incident where an unauthorized actor accessed its platform between September 18 and October 3, 2025. The actor acquired names, billing addresses, phone numbers, email addresses, and full payment card details (number, expiration, CVV). LiveRez contained the breach, engaged a cybersecurity firm for investigation, and notified affected consumers.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5f291cce063ede0fMontana State AGfiled 2025-11-20Candidate
- bd_60bc88bfbd895707New Hampshire State AGfiled 2025-11-20Verified
- bd_b26084982bd95426Maine State AGfiled 2025-11-20Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-20-liverez-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2025
- Raw hash
- 6bbf6f920cae399e6ccaf33335668a5791243b283c663662243b34e72577443f
Reporting entity
- Name
- LiveReznorm: liverez
Victim entity
- Name
- LiveReznorm: liverez
Incident
- Discovered
- Sep 18, 2025
- Materiality determined
- Oct 21, 2025
- Notification sent
- Nov 20, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.