HackingStolen CredentialsData ExfiltratedTargetedPIIIDENTITY_BASICLowContained
Moore & Van Allen PLLC
bd_4032fbc8df8a587e · schema v1 · pii pii-v1
Full breach record for Moore & Van Allen PLLC →Moore & Van Allen PLLC notified consumers of a data breach where an unauthorized actor accessed its network on August 15, 2025, for approximately 20 minutes. The actor acquired files containing personal information (PII) of clients. The firm engaged outside cybersecurity experts, contained the incident, and offered one year of Experian IdentityWorks identity protection services to affected individuals.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3a53d29015462646Leak Sitesilentransomgroupfiled 2025-09-03(29d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_a335ba5b892aed33Maine State AGfiled 2025-10-03Verified
- bd_bcbd1af7f81ee657Indiana State AGfiled 2025-10-03Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-03-moore-van-allen-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2025
- Raw hash
- 72abf4341bde6b595cf237dff4008760403e00815cfa0b758b1277f968d6c3dd
Reporting entity
- Name
- Moore & Van Allen PLLCnorm: moore van allen
- Domain
- mvalaw.com
Victim entity
- Name
- Moore & Van Allen PLLCnorm: moore van allen
- Domain
- mvalaw.com
Incident
- Discovered
- Aug 15, 2025
- Materiality determined
- Sep 3, 2025
- Notification sent
- Oct 3, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.