HackingData ExfiltratedTargetedIDENTITY_BASICLowContained
GC Services
bd_4eed0dc1feab88d6 · schema v1 · pii pii-v1
Full breach record for GC Services →GC Services notified consumers of a data security incident where unauthorized access to its network occurred between September 11 and September 20, 2023. Personal information, including names and variable data elements, may have been acquired. GC Services engaged external cybersecurity experts, notified the FBI, and offered credit monitoring services through IDX.
Vermont clock✓ VT AG ≤14 bday14 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_459779589b5e856cNew Hampshire State AGfiled 2024-01-30Verified
- bd_fc32c57d58703479Maine State AGfiled 2024-01-30Verified
- bd_3f8368515ad2e05cMaine State AGfiled 2024-01-25(5d gap)Candidate
- bd_8725b4ef8674e1b3New Hampshire State AGfiled 2024-01-25(5d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 22d gap
- bd_af38af1c89b59797Montana State AGfiled 2024-01-25(5d gap)Verified
- bd_c4f44f2ed5304f06Indiana State AGfiled 2024-01-25(5d gap)Verified
- bd_cff61c307f536256Maine State AGfiled 2024-02-21(22d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-30-gc-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2024
- Raw hash
- 45e1e98f8817c8f2fe9c83e2719e39d161774431d9dd969a798952bf2dcf6fd2
Reporting entity
- Name
- GC Servicesnorm: gc services
Victim entity
- Name
- GC Servicesnorm: gc services
Incident
- Discovered
- Jan 16, 2024
- Materiality determined
- —
- Notification sent
- Jan 30, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.