HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
Sprouse Shrader Smith PLLC
bd_4ef7b13f8d901a9b · schema v1 · pii pii-v1
Full breach record for Sprouse Shrader Smith PLLC →Sprouse Shrader Smith PLLC, a law firm, disclosed a data security incident discovered on February 25, 2025. Suspicious activity on its network led to the copying of documents containing personal information. The firm notified the FBI, engaged cybersecurity specialists, and is offering credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday13 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2eb301f061c7c9c1Indiana State AGfiled 2026-03-10Candidate
- bd_5de596b35ed93fd5Maine State AGfiled 2026-03-10Verified
- bd_73343a817e875746Indiana State AGfiled 2026-03-10Candidate
- bd_b92a9f24a528a3f1New Hampshire State AGfiled 2026-03-16(6d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 56d gap
- bd_03c5059d95a354faNew Hampshire State AGfiled 2026-04-17(38d gap)Verified
- bd_5ccacb39f9b8310fTexas State AGfiled 2026-05-05(56d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-10-sprouse-shrader-smith-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 10, 2026
- Raw hash
- ec71e69c94a2a2b5edb8e051784871803ebcda3898fe254dedc671b1da3361ef
Reporting entity
- Name
- Sprouse Shrader Smith PLLCnorm: sprouse shrader smith
Victim entity
- Name
- Sprouse Shrader Smith PLLCnorm: sprouse shrader smith
Incident
- Discovered
- Feb 25, 2025
- Materiality determined
- —
- Notification sent
- Mar 10, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the FBI and local law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(378 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.