MalwareRansomwareData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Phoenix Products
bd_4f0da5eb4a3fa8d2 · schema v1 · pii pii-v1
Full breach record for Phoenix Products →Phoenix Products, LLC notified consumers of a ransomware attack discovered on July 31, 2025. The incident potentially exposed former and current employee data, including names and Social Security numbers. The company engaged forensic specialists, reported to federal law enforcement, and offered 12 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5cd054a786741f16Indiana State AGfiled 2025-09-11Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-11-phoenix-products-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2025
- Raw hash
- 0c85a3779a45e892096854d795cd3a4f30490674a40ce50dec26e2cd341c13b0
Reporting entity
- Name
- Phoenix Productsnorm: phoenix products
- Domain
- phoenixprods.com
Victim entity
- Name
- Phoenix Productsnorm: phoenix products
- Domain
- phoenixprods.com
Incident
- Discovered
- Jul 31, 2025
- Materiality determined
- —
- Notification sent
- Sep 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported incident to federal law enforcement
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.