HackingStolen CredentialsTargetedIDENTITY_BASICCREDENTIALSLowContained
Green Mountain Higher Education Consortium
bd_4c9abb5f745f9621 · schema v1 · pii pii-v1
Full breach record for Green Mountain Higher Education Consortium →Green Mountain Higher Education Consortium notified consumers of a data breach involving unauthorized access to two employee email accounts between Oct 30 and Nov 20, 2024. The incident exposed names and other personal information. The consortium engaged forensic investigators, secured the email environment, and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday49 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_e7abcb99918b2bd5Indiana State AGfiled 2025-10-29Verified
- bd_2e095862dd9d9c72Montana State AGfiled 2025-10-28(1d gap)Candidate
- bd_839357b382bf342bMaine State AGfiled 2025-10-28(1d gap)Verified
- bd_87ae2a443c10c16dNew Hampshire State AGfiled 2025-10-28(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-29-green-mountain-higher-education-consortium-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 29, 2025
- Raw hash
- aa96e1938ed05b1752d62f096825a6750f782f30533c349edeb6567bc82b8941
Reporting entity
- Name
- Green Mountain Higher Education Consortiumnorm: green mountain higher education consortium
Victim entity
- Name
- Green Mountain Higher Education Consortiumnorm: green mountain higher education consortium
Incident
- Discovered
- Nov 19, 2024
- Materiality determined
- —
- Notification sent
- Oct 29, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 49 weeks(344 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.