Social EngineeringPhishingTargetedIDENTITY_BASICPIILowContained
Maxxis International
bd_439c73e1e8155f70 · schema v1 · pii pii-v1
Full breach record for Maxxis International →Maxxis International - USA notified consumers of a cybersecurity incident detected on October 19, 2024. An unauthorized third party accessed the network between October 17-19, 2024, after an employee clicked a malicious link. Personal information, including names and addresses, was potentially accessed. Maxxis engaged cybersecurity experts, secured the environment, reported to law enforcement, and offered 24 months of Experian IdentityWorks.
Vermont clock✗ VT AG >45 bday26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by blacksuit about this victim predates this filing by 184 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_1813d5ac108fdd2bLeak Siteblacksuitfiled 2024-11-11(161d gap)Verified by operator
Regulatory filings (1) · sorted by filing gap
- bd_2047e95b4087a37eIndiana State AGfiled 2025-04-21Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-21-maxxis-international-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2025
- Raw hash
- 1425c20a8a05db49e433acd28d4d0037e32c83bc8fa267958be28a2dc83f3bae
Reporting entity
- Name
- Maxxis Internationalnorm: maxxis international
- Domain
- maxxis.com
Victim entity
- Name
- Maxxis Internationalnorm: maxxis international
- Domain
- maxxis.com
Incident
- Discovered
- Oct 19, 2024
- Materiality determined
- —
- Notification sent
- Apr 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement and cooperated with their ongoing investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 weeks(184 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.