Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPIILowContained
VUC, Inc.
bd_436ee5c25f8f512c · schema v1 · pii pii-v1
Full breach record for VUC, Inc. →VUC, Inc. reported a cyber incident where an employee's email account was compromised via suspicious activity between Oct 10-16, 2024. The attacker accessed emails and files, potentially exposing names and other personal information. VUC secured the email tenant, launched an investigation, enhanced safeguards, provided cybersecurity training, and offered credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday22 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_eaa38fc0d70c5fa3Maryland State AGfiled 2025-03-20(1d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-19-vuc-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2025
- Raw hash
- 79acb2fb8e3b69d3a10ddd418cd196470208875a6cf9429f242b52ed16fcbb3c
Reporting entity
- Name
- VUC, Inc.norm: vuc
Victim entity
- Name
- VUC, Inc.norm: vuc
Incident
- Discovered
- Oct 16, 2024
- Materiality determined
- —
- Notification sent
- Mar 19, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notifying state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 22 weeks(154 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.