MalwareRansomwareData EncryptedRansom DemandedPIILowContained
Hertz Farm Management
bd_401328525761e9e9 · schema v1 · pii pii-v1
Full breach record for Hertz Farm Management →Hertz Farm Management Inc. notified consumers of a data breach occurring June 29, 2025, with data exfiltration confirmed on July 3, 2025. The incident involved unauthorized network access and data encryption consistent with ransomware. The company disconnected its network, engaged forensic specialists, reset passwords, and reported the incident to federal law enforcement. Credit monitoring services were offered to affected individuals.
Vermont clock✗ VT AG >45 bday23 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 167 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_7160e8351f0d526eIowa State AGfiled 2025-12-09Candidate
- bd_d0808740f53b75d6Indiana State AGfiled 2025-12-09Verified
- bd_d1f1e5b491e1efaeMontana State AGfiled 2025-12-09Verified
- bd_f88960bda229a2a3Maine State AGfiled 2025-12-09Verified
Show 1 more filing ↓Show fewer ↑up to 6d gap
- bd_982bad4979fbb6c0New Hampshire State AGfiled 2025-12-15(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-09-hertz-farm-management-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 9, 2025
- Raw hash
- 40ec3783467a47fdd6bbd0cda5a663b31c2ff2f62089df2db1ee4266486d7832
Reporting entity
- Name
- Hertz Farm Managementnorm: hertz farm management
- Domain
- hertz.ag
Victim entity
- Name
- Hertz Farm Managementnorm: hertz farm management
- Domain
- hertz.ag
Incident
- Discovered
- Jun 29, 2025
- Materiality determined
- Dec 9, 2025
- Notification sent
- Dec 9, 2025
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to federal law enforcement
Compliance
- Time to disclose
- 23 weeks(163 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.