HackingStolen CredentialsEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Cupertino Electric, Inc.
bd_4ad2f77a2f6a6067 · schema v1 · pii pii-v1
Full breach record for Cupertino Electric, Inc. →Cupertino Electric, Inc. notified Vermont AG of a data breach affecting employee data (name, SSN, DOB, driver's license). Unauthorized access occurred June 14-24, 2023. CEI engaged forensic specialists, is reviewing security policies, and offering 24 months of credit monitoring to affected employees. Status is active.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3b619123cbca56e0Washington State AGfiled 2023-07-28Candidate
- bd_7d70eaf709b6e700Oregon State AGfiled 2023-07-28Verified
- bd_863296c1931dc209Montana State AGfiled 2023-07-28Verified
- bd_bd7803ba872c3246New Hampshire State AGfiled 2023-07-28Verified
Show 2 more filings ↓Show fewer ↑
- bd_be562e41fe0fdd3aMaine State AGfiled 2023-07-28Verified
- bd_c22d29c83d49512dCalifornia State AGfiled 2023-07-28Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-28-cupertino-electric-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- b9fa37673c7daef221c2151e8279040c970a92625c39d34789edc29fa8fc77bc
Reporting entity
- Name
- Cupertino Electric, Inc.norm: cupertino electric
Victim entity
- Name
- Cupertino Electric, Inc.norm: cupertino electric
Incident
- Discovered
- Jun 24, 2023
- Materiality determined
- —
- Notification sent
- Jul 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Will notify applicable regulatory authorities, as required by law
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.